First published: Fri Sep 05 2014(Updated: )
IBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restrictions by visiting the Rights page and then following a generated link.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos TM1 | =10.2.0.2 | |
IBM Cognos TM1 | =10.2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0877 has a medium severity rating due to the potential for access restriction bypass.
To fix CVE-2014-0877, upgrade IBM Cognos TM1 to version 10.2.0.2 IF1 or 10.2.2.0 IF1 or later.
IBM Cognos TM1 versions 10.2.0.2 before IF1 and 10.2.2.0 before IF1 are affected by CVE-2014-0877.
Yes, CVE-2014-0877 can be exploited remotely by attackers to bypass access restrictions.
CVE-2014-0877 is an access control vulnerability that allows unauthorized actions via a generated link.