First published: Sun Oct 04 2015(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Tivoli Common Reporting (TCR) 2.1 before IF13 and 2.1.1 before IF21, and TCR 3.1.x as used in Cognos Business Intelligence before 10.2 IF0015 and other products, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Common Reporting | =2.1.0.0 | |
IBM Tivoli Common Reporting | =2.1.1.0 | |
IBM Tivoli Common Reporting | =3.1.0.0 | |
IBM Tivoli Common Reporting | =3.1.0.1 | |
IBM Tivoli Common Reporting | =3.1.0.2 | |
IBM Tivoli Common Reporting | =3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1969 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2015-1969, upgrade to IBM Tivoli Common Reporting versions 2.1.1 IF21 or later, or 3.1.x to a patched release.
Users of IBM Tivoli Common Reporting versions 2.1 through 2.1.1 and 3.1.x are affected by CVE-2015-1969.
CVE-2015-1969 is a cross-site scripting (XSS) vulnerability that allows attackers to inject scripts into web pages.
No, CVE-2015-1969 requires authentication, allowing only remote authenticated users to exploit the vulnerability.