CVE Vulnerabilities

CVE-2019-4589

Improper Privilege Management

Published: Aug 03, 2020 | Modified: Aug 03, 2020
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the My schedules and subscriptions page is visible and accessible to a less privileged user. IBM X-Force ID: 167449.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Cognos_analytics Ibm 11.0.0 (including) 11.0.0 (including)
Cognos_analytics Ibm 11.1.0 (including) 11.1.0 (including)

Potential Mitigations

References