IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7183597 |
![]() ![]() |
History
Wed, 19 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 19 Feb 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
Title | IBM Cognos Controller XML external entity injection | |
Weaknesses | CWE-611 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published: 2025-02-19T16:20:09.058Z
Updated: 2025-02-19T16:44:46.227Z
Reserved: 2023-10-31T00:13:45.654Z
Link: CVE-2023-47160

Updated: 2025-02-19T16:44:30.339Z

Status : Received
Published: 2025-02-19T17:15:13.983
Modified: 2025-02-19T17:15:13.983
Link: CVE-2023-47160

No data.