IBM Cognos Controller
cpe:2.3:a:ibm:cognos_controller:*:*:*:*:*:*:*
- 11.1.0
- 11.0.0
- 11.0.1
A Client-Side Desync (CSD) vulnerability has been identified in IBM Cognos Controller versions 11.0.0 through 11.1.0. This vulnerability allows an attacker to exploit a desynchronized browser connection, potentially leading to Cross-Site Scripting (XSS) attacks.
Exploitation of this vulnerability could result in Cross-Site Scripting (XSS) attacks.
Users are advised to upgrade to IBM Cognos Controller 11.0.1 FP4 or IBM Controller 11.1.0 FP3. For Cloud deployments, version 11.1.0.3 is available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.