First published: Tue Mar 05 2013(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is not properly handled during rendering of stored data.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence | =8.4.1 | |
IBM Cognos Business Intelligence | =10.1 | |
IBM Cognos Business Intelligence | =10.1.1 | |
IBM Cognos Business Intelligence | =10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4836 has a medium severity level as it allows remote authenticated users to inject arbitrary web scripts or HTML.
To mitigate CVE-2012-4836, upgrade to IBM Cognos Business Intelligence version 8.4.1 IF1, 10.1 IF2, 10.1.1 IF2, or 10.2 IF1.
CVE-2012-4836 affects users of IBM Cognos Business Intelligence versions 8.4.1, 10.1, 10.1.1, and 10.2 before their respective fix packs.
CVE-2012-4836 is classified as a cross-site scripting (XSS) vulnerability.
No, CVE-2012-4836 can only be exploited by remote authenticated users.