First published: Wed Mar 08 2017(Updated: )
IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user. IBM Reference #: 1999671.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence | =10.1.1 | |
IBM Cognos Business Intelligence | =10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9985 has been classified as a medium severity vulnerability due to the exposure of sensitive information in log files.
To fix CVE-2016-9985, ensure that log files are secured and sensitive information is not stored in a readable format.
CVE-2016-9985 affects IBM Cognos Server versions 10.1.1 and 10.2.
CVE-2016-9985 exposes highly sensitive information that is stored in the log files of the affected IBM Cognos versions.
Any local user with access to the system can read the sensitive information exposed by CVE-2016-9985.