Loading HuntDB...

GHSA-rcv3-9mhc-v9jf

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to obtain sensitive information, caused by a flaw in the HTTP OPTIONS method, aka Optionsbleed. By sending an OPTIONS HTTP request, a remote attacker could exploit this vulnerability to read secret data from process memory and obtain sensitive information. IBM X-Force ID: 158878.

Related CVEs

Key Information

GHSA ID
GHSA-rcv3-9mhc-v9jf
Published
May 24, 2022 4:48 PM
Last Modified
February 3, 2023 9:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 1, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.