First published: Sat Mar 02 2013(Updated: )
Cross-site scripting (XSS) vulnerability in Query Studio in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows user-assisted remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence | =8.4.1 | |
IBM Cognos Business Intelligence | =10.1 | |
IBM Cognos Business Intelligence | =10.1.1 | |
IBM Cognos Business Intelligence | =10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2193 is classified as a moderate severity vulnerability due to the potential for user-assisted attacks.
To remediate CVE-2012-2193, upgrade IBM Cognos Business Intelligence to a version that includes the appropriate security patches, specifically IF1 for 8.4.1 and IF2 for the 10.1 and 10.2 versions.
CVE-2012-2193 affects IBM Cognos Business Intelligence versions 8.4.1, 10.1, 10.1.1, and 10.2.
CVE-2012-2193 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
CVE-2012-2193 requires user assistance for exploitation, meaning an attacker must trick users into performing actions that trigger the vulnerability.