CVE Vulnerabilities

CVE-2023-38009

Improper Certificate Validation

Published: Jan 26, 2025 | Modified: Aug 18, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Cognos_analytics Ibm 1.1 (including) 1.1 (including)

Potential Mitigations

References