First published: Sun Jul 03 2016(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence | =10.1.1 | |
IBM Cognos Business Intelligence | =10.2 | |
IBM Cognos Business Intelligence | =10.2.1 | |
IBM Cognos Business Intelligence | =10.2.1.1 | |
IBM Cognos Business Intelligence | =10.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0221 is classified as a medium severity vulnerability due to the potential for unauthorized script execution by authenticated users.
To fix CVE-2016-0221, upgrade IBM Cognos TM1 to a version prior to the known vulnerable releases, specifically version 10.1.1 IF19 or more recent.
CVE-2016-0221 affects users of IBM Cognos TM1, particularly those utilizing IBM Cognos Business Intelligence versions 10.1.1 and 10.2.x.
The impact of CVE-2016-0221 allows remote authenticated users to inject arbitrary web scripts or HTML, potentially compromising sensitive data.
Yes, CVE-2016-0221 is exploitable remotely by authenticated users who can craft specific URLs to execute scripts.