CVE-2020-4561 CRITICAL

CVE-2020-4561

Vendor Ibm
Product Cognos Analytics
Published May 31, 2021
Last update September 17, 2024

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/PR:N/C:H/I:H/S:C/AC:L/A:H/UI:N/AV:N/RL:O/E:U/RC:C

What the vulnerability does

01Description

IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write files to the Cognos Analytics system. IBM X-Force ID: 183903.

Key dates

02Disclosure timeline

May 31, 2021 CVE published
September 17, 2024 Record updated