First published: Tue Mar 05 2013(Updated: )
IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java serialized input, which allows remote attackers to execute arbitrary commands via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence | =8.4.1 | |
IBM Cognos Business Intelligence | =10.1 | |
IBM Cognos Business Intelligence | =10.1.1 | |
IBM Cognos Business Intelligence | =10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4858 is considered a high-severity vulnerability due to its potential for remote command execution.
To fix CVE-2012-4858, update your IBM Cognos Business Intelligence to a version that includes the necessary patches, specifically versions 8.4.1 IF1 and 10.1 IF2 or later.
CVE-2012-4858 affects IBM Cognos Business Intelligence versions 8.4.1, 10.1, 10.1.1, and 10.2 before specific interim fixes.
Yes, CVE-2012-4858 can be exploited remotely as it allows attackers to execute arbitrary commands through improper validation of Java serialized input.
The potential impacts of CVE-2012-4858 include unauthorized remote code execution, leading to loss of data integrity and confidentiality.