Vulnerabilities > IBM > Cognos Business Intelligence > 10.2.1.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-04-23 | CVE-2017-1764 | Insufficiently Protected Credentials vulnerability in IBM Cognos Business Intelligence IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local user. | 7.0 |
2018-04-23 | CVE-2017-1486 | Cross-site Scripting vulnerability in IBM Cognos Business Intelligence IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2 is vulnerable to cross-site scripting. | 6.1 |
2017-06-07 | CVE-2016-0254 | XXE vulnerability in IBM Cognos Business Intelligence IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. | 6.5 |
2017-03-27 | CVE-2016-8960 | Permissions, Privileges, and Access Controls vulnerability in IBM Cognos Business Intelligence IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by intercepting the higher-privilege user's cookie value from its HTTP request and then reusing it in subsequent requests. | 8.8 |
2017-02-01 | CVE-2016-0218 | Cross-site Scripting vulnerability in IBM Cognos Business Intelligence IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied input. | 5.4 |
2016-07-03 | CVE-2016-0346 | Cross-site Scripting vulnerability in IBM Cognos Business Intelligence Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | 5.4 |
2016-07-03 | CVE-2016-0221 | Cross-site Scripting vulnerability in IBM Cognos Business Intelligence Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | 5.4 |