First published: Sun Jul 03 2016(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence | =10.1.1 | |
IBM Cognos Business Intelligence | =10.2 | |
IBM Cognos Business Intelligence | =10.2.1 | |
IBM Cognos Business Intelligence | =10.2.1.1 | |
IBM Cognos Business Intelligence | =10.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0346 is considered a medium severity vulnerability due to its ability to allow remote authenticated users to inject malicious scripts.
CVE-2016-0346 affects IBM Cognos Business Intelligence versions 10.1.1, 10.2, 10.2.1, 10.2.1.1, and 10.2.2 before their respective fix packs.
To mitigate CVE-2016-0346, update your IBM Cognos Business Intelligence to the latest available fix pack.
CVE-2016-0346 can enable cross-site scripting (XSS) attacks, allowing attackers to execute arbitrary web scripts or HTML in victims' browsers.
Yes, exploitation of CVE-2016-0346 requires an attacker to be a remote authenticated user.