Vulnerability Details CVE-2022-39163
IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack where an attacker could exploit a desynchronized browser connection that could lead to further cross-site scripting (XSS) attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.8%
CVSS Severity
CVSS v3 Score 4.7
Products affected by CVE-2022-39163
-
cpe:2.3:a:ibm:cognos_controller:11.0.0
-
cpe:2.3:a:ibm:cognos_controller:11.0.1
-
cpe:2.3:a:ibm:controller:11.1.0
-
cpe:2.3:o:microsoft:windows:-