IBM Cognos Controller
cpe:2.3:a:ibm:cognos_controller:*:*:*:*:*:*:*
- >= 11.0.0, <= 11.0.1
A vulnerability exists in IBM Cognos Controller versions 11.0.0 to 11.0.1 and IBM Controller versions 11.1.0 to 11.1.1. The issue arises from the use of hardcoded cryptographic keys for signing session cookies, which could allow an attacker to obtain sensitive information.
Exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive information.
Users are advised to apply the available interim fix through IBM Fix Central. Instructions for downloading the patch are available on the IBM Support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.