VDB

CVE-2023-47160

CVE-2023-47160 PUBLISHED CVSS 8.199999809265137 HIGH

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

EPSS 0.06% · 17.8th percentile

Risk Scores

CVSS v3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
EPSS Score
0.06%
17.8th percentile

Affected Products

VendorProductVersions
IBMController11.1.0, 11.1.0
ibmcontroller11.1.0, 11.1.0, 11.1.0
ibmcognos_controller11.0.0, 11.0.0, 11.0.0
IBMCognos Controller11.0.0, 11.0.0

Timeline

  • Feb 19, 2025 CVE Published
  • Feb 19, 2025 PoC Published
  • Feb 19, 2025 PoC Published
  • Feb 19, 2025 PoC Published
  • Feb 20, 2025 EPSS Score
  • Mar 6, 2025 EPSS Score
  • Mar 20, 2025 EPSS Score
  • Apr 4, 2025 EPSS Score
  • Apr 18, 2025 EPSS Score
  • May 2, 2025 EPSS Score
  • May 16, 2025 EPSS Score
  • May 31, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›