Vulnerabilities > IBM > Cognos Business Intelligence > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-04-23 | CVE-2017-1486 | Cross-site Scripting vulnerability in IBM Cognos Business Intelligence IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2 is vulnerable to cross-site scripting. | 6.1 |
2017-06-07 | CVE-2016-0254 | XXE vulnerability in IBM Cognos Business Intelligence IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. | 6.5 |
2017-04-17 | CVE-2016-3038 | Cross-site Scripting vulnerability in IBM Cognos Business Intelligence 10.1/10.2/10.2.2 IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. | 5.4 |
2017-04-17 | CVE-2016-3037 | Information Exposure vulnerability in IBM Cognos Business Intelligence 10.1/10.2/10.2.2 IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. | 5.7 |
2017-03-08 | CVE-2016-9985 | Information Exposure Through Log Files vulnerability in IBM Cognos Business Intelligence 10.1.1/10.2 IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user. | 5.5 |
2017-02-01 | CVE-2016-0218 | Cross-site Scripting vulnerability in IBM Cognos Business Intelligence IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied input. | 5.4 |
2016-07-03 | CVE-2016-0346 | Cross-site Scripting vulnerability in IBM Cognos Business Intelligence Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | 5.4 |
2016-07-03 | CVE-2016-0221 | Cross-site Scripting vulnerability in IBM Cognos Business Intelligence Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | 5.4 |