First published: Fri Apr 12 2013(Updated: )
The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Disclosure Management | =10.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0501 has a high severity rating due to its potential to allow remote code execution.
To fix CVE-2013-0501, update the IBM Cognos Disclosure Management to the latest version provided by IBM.
CVE-2013-0501 affects systems using IBM Cognos Disclosure Management version 10.2.0 and the Edraw Office Viewer Component.
CVE-2013-0501 allows attackers to read arbitrary files and potentially execute unauthorized programs on a client machine.
While CVE-2013-0501 is recognized, the extent of its exploitation may vary and depend on the usage of affected software.