First published: Tue Aug 27 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence Server | =8.4.1 | |
IBM Cognos Business Intelligence Server | =10.1 | |
IBM Cognos Business Intelligence Server | =10.1.1 | |
IBM Cognos Business Intelligence Server | =10.2 | |
IBM Cognos Business Intelligence Server | =10.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0586 is classified as a moderate severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
To fix CVE-2013-0586, ensure you update to the latest patched version of IBM Cognos Business Intelligence.
CVE-2013-0586 affects remote authenticated users of IBM Cognos Business Intelligence versions 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1.
CVE-2013-0586 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web script or HTML.
CVE-2013-0586 was discovered and publicly disclosed in 2013.