Rewterz
Rewterz Threat Advisory – CVE-2021-44879 – Linux Kernel Vulnerability
February 15, 2022
Rewterz
Rewterz Threat Alert – RedLine Stealer – Active IOCs
February 15, 2022

Rewterz Threat Advisory – Multiple IBM Cognos Analytics Mobile for Android Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2021-39080 

Due to weak obfuscation, IBM Cognos Analytics Mobile for Android application prior to version 1.1.14 , an attacker could be able to reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used.

CVE-2021-39079 

IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Impact

  • Information Disclosure
  • Cross-Site Scripting

Indicators of Compromise

CVE

  • CVE-2021-39080
  • CVE-2021-39079

Affected Vendors

IBM

Affected Products

  • IBM Cognos Analytics Mobile 1.1

Remediation

Refer to IBM Security Bulletin for patch, upgrade or suggested workaround information.

https://www.ibm.com/support/pages/node/6555140