VDB

CVE-2021-29679

CVE-2021-29679 PUBLISHED CVSS 8.800000190734863 HIGH

IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915.

EPSS 0.72% · 72.8th percentile

Risk Scores

CVSS v3.0
8.800000190734863
CVSS:3.0/PR:L/AV:N/S:U/A:H/UI:N/I:H/AC:L/C:H/E:U/RL:O/RC:C
EPSS Score
0.72%
72.8th percentile

Affected Products

VendorProductVersions
ibmcognos_analytics11.2.0, 11.1.7
IBMCognos Analytics11.2.0, 11.1.7
netapponcommand_insight

Timeline

  • Oct 15, 2021 CVE Published
  • Oct 16, 2021 EPSS Score
  • Oct 22, 2021 EPSS Score
  • Dec 11, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 6, 2022 EPSS Score
  • Apr 3, 2022 EPSS Score
  • May 29, 2022 EPSS Score
  • Jul 26, 2022 EPSS Score
  • Sep 20, 2022 EPSS Score
  • Jan 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›