First published: Fri Jan 26 2018(Updated: )
IBM Cognos TM1 10.2 and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129617.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos TM1 | =10.2 | |
IBM Cognos TM1 | =10.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1506 is classified as a critical vulnerability due to its potential for credential disclosure through cross-site scripting.
To fix CVE-2017-1506, upgrade your IBM Cognos TM1 to the latest version provided by IBM that addresses this vulnerability.
CVE-2017-1506 affects IBM Cognos TM1 versions 10.2 and 10.2.2.
Users of affected versions may be subjected to arbitrary JavaScript execution, potentially leading to unauthorized access to sensitive information.
Currently, there is no documented workaround for CVE-2017-1506; updating to a fixed version is the recommended action.