CVE-2013-2978: Path Traversal
Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CVE-2013-2988.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2978?
CVE-2013-2978 is classified as a medium severity vulnerability due to its ability to allow remote authenticated users unauthorized file access.
How do I fix CVE-2013-2978?
To fix CVE-2013-2978, update IBM Cognos Business Intelligence to the latest version that addresses this vulnerability.
Who is affected by CVE-2013-2978?
CVE-2013-2978 affects users of IBM Cognos Business Intelligence versions 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1.
What type of vulnerability is CVE-2013-2978?
CVE-2013-2978 is an absolute path traversal vulnerability that can be exploited to read arbitrary files on the server.
Can CVE-2013-2978 be exploited by unauthenticated users?
No, CVE-2013-2978 requires an authenticated user with Report Author privileges to be exploited.