First published: Mon Nov 18 2013(Updated: )
IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence | =8.4.1 | |
IBM Cognos Business Intelligence | =10.1 | |
IBM Cognos Business Intelligence | =10.1.1 | |
IBM Cognos Business Intelligence | =10.2 | |
IBM Cognos Business Intelligence | =10.2.1 | |
IBM Cognos Business Intelligence | =10.2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4034 is categorized as a medium severity vulnerability.
To fix CVE-2013-4034, upgrade to IBM Cognos Business Intelligence versions 8.4.1 IF3, 10.1.0 IF4, or higher.
CVE-2013-4034 allows remote authenticated users to perform XPath injection to read arbitrary files.
CVE-2013-4034 affects IBM Cognos Business Intelligence versions 8.4.1, 10.1.0, 10.1.1, 10.2.0, 10.2.1, and 10.2.1.1 before specific intermediate fixes.
Yes, CVE-2013-4034 is a remote vulnerability that requires authentication to exploit.