First published: Tue Aug 27 2013(Updated: )
Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CVE-2013-2978.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence | =8.4.1 | |
IBM Cognos Business Intelligence | =10.1 | |
IBM Cognos Business Intelligence | =10.1.1 | |
IBM Cognos Business Intelligence | =10.2 | |
IBM Cognos Business Intelligence | =10.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2988 has a moderate severity level due to the potential for unauthorized file access by authenticated users.
To fix CVE-2013-2988, upgrade to IBM Cognos Business Intelligence version 10.2.2 or later, where this vulnerability has been addressed.
CVE-2013-2988 affects users of IBM Cognos Business Intelligence versions 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1.
CVE-2013-2988 allows remote authenticated users to exploit path traversal to access sensitive files on the server.
If unable to upgrade, consider isolating the affected system from the network and limiting user permissions until a fix can be applied.