Lucene search

K
cveIbmCVE-2012-4840
HistoryMar 05, 2013 - 5:02 a.m.

CVE-2012-4840

2013-03-0505:02:08
CWE-94
ibm
web.nvd.nist.gov
32
ibm cognos
bi
xpath
injection
vulnerability
nvd
cve-2012-4840

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

64.8%

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XPath injection attacks, and call XPath extension functions, via unspecified vectors.

Affected configurations

Nvd
Node
ibmcognos_business_intelligenceMatch8.4.1
OR
ibmcognos_business_intelligenceMatch10.1
OR
ibmcognos_business_intelligenceMatch10.1.1
OR
ibmcognos_business_intelligenceMatch10.2
VendorProductVersionCPE
ibmcognos_business_intelligence8.4.1cpe:2.3:a:ibm:cognos_business_intelligence:8.4.1:*:*:*:*:*:*:*
ibmcognos_business_intelligence10.1cpe:2.3:a:ibm:cognos_business_intelligence:10.1:*:*:*:*:*:*:*
ibmcognos_business_intelligence10.1.1cpe:2.3:a:ibm:cognos_business_intelligence:10.1.1:*:*:*:*:*:*:*
ibmcognos_business_intelligence10.2cpe:2.3:a:ibm:cognos_business_intelligence:10.2:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

64.8%

Related for CVE-2012-4840