PublicCVE

CVE-2020-4520

HIGH7.1JSON exportCreate alert

Description

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395.

CVSS breakdown

CVSS 3.0
Confidentiality
High
Privileges Required
Low
Scope
Unchanged
Integrity
High
User Interaction
Required
Attack Vector
Network
Attack Complexity
High
Availability
High
RC
Changed
E
Unchanged
RL
O

Affected products