Medium severity6.5NVD Advisory· Published Feb 26, 2024· Updated Jun 17, 2026
CVE-2022-34357
CVE-2022-34357
Description
IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a period of time making service unavailable for other legitimate users. IBM X-Force ID: 230510.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*range: >=11.1.1,<11.1.7
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:-:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack1:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack2:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack3:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack4:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack5:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack6:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.1.7:fixpack7:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:12.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:cognos_analytics:12.0.1:*:*:*:*:*:*:*
- (no CPE)range: 11.1.7, 11.2.4, 12.0.0
- (no CPE)range: 11.1.7, 11.2.4, 12.0.0
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
- Range: 11.1.7, 11.2.4, 12.0.0
Patches
Vulnerability mechanics
References
4- exchange.xforce.ibmcloud.com/vulnerabilities/230510nvdVDB EntryVendor Advisory
- security.netapp.com/advisory/ntap-20240405-0001/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20240621-0006/nvdThird Party Advisory
- www.ibm.com/support/pages/node/7123154nvdVendor Advisory
News mentions
0No linked articles in our index yet.