IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system.
Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cognos_analytics | Ibm | 11.2.0 (including) | 11.2.4 (including) |
Cognos_analytics | Ibm | 12.0.0 (including) | 12.0.4 (including) |
Cognos_analytics | Ibm | 11.2.4-fixpack1 (including) | 11.2.4-fixpack1 (including) |
Cognos_analytics | Ibm | 11.2.4-fixpack2 (including) | 11.2.4-fixpack2 (including) |
Cognos_analytics | Ibm | 11.2.4-fixpack3 (including) | 11.2.4-fixpack3 (including) |