← back
CVE-2022-36773high

CVE-2022-36773

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.1epss 1.9%
exploitation probability
1.9%top 21% of all CVEs
observed exploitation
nono source reports it
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.
CVSS:3.0/AC:L/I:N/AV:N/C:H/A:L/UI:N/S:U/PR:L/RC:C/RL:O/E:U
Affected products
IBM · Cognos Analytics