CVE-2022-39163

IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack where an attacker could exploit a desynchronized browser connection that could lead to further cross-site scripting (XSS) attacks.
Configurations

No configuration.

History

27 Mar 2025, 16:45

Type Values Removed Values Added
Summary
  • (es) IBM Cognos Controller 11.0.0 a 11.1.0 es vulnerable a un ataque de Client-Side Desync (CSD) donde un atacante podría explotar una conexión de navegador desincronizada que podría conducir a otros ataques de cross-site scripting (XSS).

26 Mar 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-26 14:15

Updated : 2025-03-27 16:45


NVD link : CVE-2022-39163

Mitre link : CVE-2022-39163

CVE.ORG link : CVE-2022-39163


JSON object : View

Products Affected

No product.

CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')