Vulnerabilities > IBM > Cognos Business Intelligence > Low

DATE CVE VULNERABILITY TITLE RISK
2018-04-23 CVE-2017-1764 Insufficiently Protected Credentials vulnerability in IBM Cognos Business Intelligence
IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local user.
local
ibm CWE-522
1.9
2017-04-17 CVE-2016-3037 Information Exposure vulnerability in IBM Cognos Business Intelligence 10.1/10.2/10.2.2
IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key.
network
ibm CWE-200
3.5
2017-04-17 CVE-2016-3038 Cross-site Scripting vulnerability in IBM Cognos Business Intelligence 10.1/10.2/10.2.2
IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting.
network
ibm CWE-79
3.5
2017-03-08 CVE-2016-9985 Information Exposure Through Log Files vulnerability in IBM Cognos Business Intelligence 10.1.1/10.2
IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user.
local
low complexity
ibm CWE-532
2.1
2017-02-01 CVE-2016-0218 Cross-site Scripting vulnerability in IBM Cognos Business Intelligence
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
network
ibm CWE-79
3.5
2016-07-03 CVE-2016-0221 Cross-site Scripting vulnerability in IBM Cognos Business Intelligence
Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
3.5
2016-07-03 CVE-2016-0346 Cross-site Scripting vulnerability in IBM Cognos Business Intelligence
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
3.5
2014-12-12 CVE-2014-6145 Cross-Site Scripting vulnerability in IBM Cognos Business Intelligence
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence 10.1 before IF10, 10.1.1 before IF9, 10.2 before IF11, 10.2.1 before IF8, and 10.2.1.1 before IF7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
3.5
2014-02-22 CVE-2014-0861 Cross-Site Scripting vulnerability in IBM Cognos Business Intelligence
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled during use of the Back button.
network
ibm CWE-79
3.5
2013-08-27 CVE-2013-0586 Cross-Site Scripting vulnerability in IBM Cognos Business Intelligence
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
3.5