VDB
CVE-2022-38707
CVE-2022-38707
PUBLISHED
CVSS 4 MEDIUM
IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179.
EPSS 0.16% · 6.0th percentile
Risk Scores
CVSS 3.1
4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.16%
6.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ibm | cognos_command_center | 10.2.4.1 |
| IBM | Cognos Command Center | 10.2.4.1 |
Timeline
- Apr 22, 2022 PoC Published
- May 5, 2023 CVE Published
- May 6, 2023 EPSS Score
- Jun 12, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Aug 25, 2023 EPSS Score
- Oct 1, 2023 EPSS Score
- Nov 7, 2023 EPSS Score
- Dec 14, 2023 EPSS Score
- Jan 20, 2024 EPSS Score
- Feb 25, 2024 EPSS Score
- Apr 2, 2024 EPSS Score