First published: Fri May 04 2012(Updated: )
Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted data.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos TM1 | =9.4.1 | |
IBM Cognos TM1 | =9.4.1.3 | |
IBM Cognos TM1 | =9.5.1 | |
IBM Cognos TM1 | =9.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0202 is classified as a high severity vulnerability due to its potential to cause denial of service or allow arbitrary code execution.
The recommended fix for CVE-2012-0202 is to update IBM Cognos TM1 to version 9.5.2 FP2 or later.
CVE-2012-0202 affects IBM Cognos TM1 versions 9.4.1, 9.4.1.3, 9.5.1, and 9.5.2 prior to FP2.
CVE-2012-0202 can be exploited by remote attackers to crash the daemon or potentially execute arbitrary code.
Currently, there are no reliable workarounds for CVE-2012-0202, and updating the software is the best course of action.