First published: Wed Jun 07 2017(Updated: )
IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a file from the local system, which could allow the attacker to obtain sensitive information. IBM X-Force ID: 119618.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence Server | =10.1.1 | |
IBM Cognos Business Intelligence Server | =10.2.0 | |
IBM Cognos Business Intelligence Server | =10.2.1 | |
IBM Cognos Business Intelligence Server | =10.2.1.1 | |
IBM Cognos Business Intelligence Server | =10.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9710 has been classified as a high severity vulnerability.
To mitigate CVE-2016-9710, users should upgrade to a patched version of IBM Cognos Business Intelligence Server.
CVE-2016-9710 allows remote attackers to include arbitrary files, potentially exposing sensitive information.
CVE-2016-9710 affects IBM Cognos Business Intelligence Server versions 10.1.1, 10.2.0, 10.2.1, 10.2.1.1, and 10.2.2.
Yes, CVE-2016-9710 can be exploited by remote attackers through specially-crafted URLs.