First published: Tue Mar 05 2013(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence | =8.4.1 | |
IBM Cognos Business Intelligence | =10.1 | |
IBM Cognos Business Intelligence | =10.1.1 | |
IBM Cognos Business Intelligence | =10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4835 has a moderate severity level due to the potential for cross-site scripting attacks.
To fix CVE-2012-4835, upgrade IBM Cognos Business Intelligence to versions 8.4.1 IF1, 10.1 IF2, 10.1.1 IF2, or 10.2 IF1.
CVE-2012-4835 affects IBM Cognos Business Intelligence versions 8.4.1, 10.1, 10.1.1, and 10.2.
CVE-2012-4835 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2012-4835 can potentially lead to data breaches by allowing attackers to inject malicious scripts.