{ "dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": { "state": "PUBLISHED", "cveId": "CVE-2020-4301", "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "datePublished": "2022-09-01T19:00:24.592Z", "dateUpdated": "2024-09-17T00:06:09.107Z", "dateReserved": "2019-12-30T00:00:00.000Z" }, "containers": { "cna": { "datePublic": "2022-08-31T00:00:00.000Z", "providerMetadata": { "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm", "dateUpdated": "2022-10-14T00:00:00.000Z" }, "descriptions": [ { "lang": "en", "value": "IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609." } ], "affected": [ { "vendor": "IBM", "product": "Cognos Analytics", "versions": [ { "version": "11.2.0", "status": "affected" }, { "version": "11.1.7", "status": "affected" }, { "version": "11.2.1", "status": "affected" } ] } ], "references": [ { "url": "https://www.ibm.com/support/pages/node/6615285" }, { "name": "ibm-cognos-cve20204301-csrf (176609)", "tags": [ "vdb-entry" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/176609" }, { "url": "https://security.netapp.com/advisory/ntap-20221014-0005/" } ], "metrics": [ { "cvssV3_0": { "version": "3.0", "vectorString": "CVSS:3.0/AC:L/I:L/C:N/AV:N/UI:R/A:N/S:U/PR:N/RC:C/E:U/RL:O", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE", "exploitCodeMaturity": "UNPROVEN", "remediationLevel": "OFFICIAL_FIX", "reportConfidence": "CONFIRMED", "baseScore": 4.3, "temporalScore": 3.8, "baseSeverity": "MEDIUM", "temporalSeverity": "LOW" } } ], "problemTypes": [ { "descriptions": [ { "type": "text", "description": "Gain Access", "lang": "en" } ] } ] }, "adp": [ { "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-04T08:00:06.960Z" }, "title": "CVE Program Container", "references": [ { "url": "https://www.ibm.com/support/pages/node/6615285", "tags": [ "x_transferred" ] }, { "name": "ibm-cognos-cve20204301-csrf (176609)", "tags": [ "vdb-entry", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/176609" }, { "url": "https://security.netapp.com/advisory/ntap-20221014-0005/", "tags": [ "x_transferred" ] } ] } ] } }