CVE-2023-30996
CVE-2023-30996 is a medium-severity vulnerability in Ibm Cognos Analytics with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-346.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 0% (36th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2023-35334
- Weakness: CWE-346
- Affected product: Ibm Cognos Analytics
- Published:
- Last modified:
Description
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.
Frequently asked questions
- What is CVE-2023-30996?
- IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.
- How severe is CVE-2023-30996?
- CVE-2023-30996 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2023-30996 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (36th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-30996?
- CVE-2023-30996 primarily affects Ibm Cognos Analytics. In total, 15 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2023-30996?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2023-30996 have an EU (EUVD) identifier?
- Yes. CVE-2023-30996 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2023-35334.
- When was CVE-2023-30996 published?
- CVE-2023-30996 was published on 2024-02-26 and last updated on 2026-06-17.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/254290
- https://security.netapp.com/advisory/ntap-20240405-0004/
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://www.ibm.com/support/pages/node/7123154
Affected products (15)
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:-:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack1:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack2:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack3:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack4:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack5:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack6:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack7:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:12.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:12.0.1:*:*:*:*:*:*:*
More vulnerabilities in Ibm Cognos Analytics
- CVE-2020-4561 — Critical (CVSS 10.0): IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This…
- CVE-2021-38945 — Critical (CVSS 9.8): IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by…
- CVE-2020-4377 — Critical (CVSS 9.1): IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML…
- CVE-2024-51466 — Critical (CVSS 9.0): IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language…
- CVE-2021-38886 — High (CVSS 8.8): IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an…
- CVE-2021-29756 — High (CVSS 8.8): IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which…
All CVEs affecting Ibm Cognos Analytics →
Other CWE-346 vulnerabilities
- CVE-2026-42901 — Critical (CVSS 10.0): Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-16375 — Critical (CVSS 9.8): Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR…
- CVE-2026-16358 — Critical (CVSS 9.8): Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR…
- CVE-2026-16349 — Critical (CVSS 9.8): Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR…
- CVE-2023-49899 — Critical (CVSS 9.8): An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the…
- CVE-2026-6508 — Critical (CVSS 9.8): Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows…