Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-34357


IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a period of time making service unavailable for other legitimate users. IBM X-Force ID: 230510.


Published

2024-02-26T16:27:45.427

Last Modified

2024-12-17T16:49:34.733

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application netapp oncommand_insight - Yes
Application ibm cognos_analytics < 11.1.7 Yes
Application ibm cognos_analytics < 11.2.4 Yes
Application ibm cognos_analytics 11.1.7 Yes
Application ibm cognos_analytics 11.1.7 Yes
Application ibm cognos_analytics 11.1.7 Yes
Application ibm cognos_analytics 11.1.7 Yes
Application ibm cognos_analytics 11.1.7 Yes
Application ibm cognos_analytics 11.1.7 Yes
Application ibm cognos_analytics 11.1.7 Yes
Application ibm cognos_analytics 11.1.7 Yes
Application ibm cognos_analytics 11.2.4 Yes
Application ibm cognos_analytics 11.2.4 Yes
Application ibm cognos_analytics 11.2.4 Yes
Application ibm cognos_analytics 12.0.0 Yes
Application ibm cognos_analytics 12.0.1 Yes

References