Vulnerabilities > IBM > Cognos Express

DATE CVE VULNERABILITY TITLE RISK
2014-03-25 CVE-2013-5445 Cryptographic Issues vulnerability in IBM Cognos Express
IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext information by leveraging knowledge of a static decryption key.
network
low complexity
ibm CWE-310
5.0
2014-03-25 CVE-2013-5444 Cryptographic Issues vulnerability in IBM Cognos Express
The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encrypted credentials via unspecified vectors.
network
low complexity
ibm CWE-310
5.0
2014-03-25 CVE-2013-5443 Cross-Site Request Forgery (CSRF) vulnerability in IBM Cognos Express
Cross-site request forgery (CSRF) vulnerability in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to hijack the authentication of arbitrary users.
network
ibm CWE-352
6.8
2010-02-05 CVE-2010-0557 Credentials Management vulnerability in IBM Cognos Express 9.0
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials.
network
low complexity
ibm CWE-255
7.5