Lucene search

K
ibmIBM7470FAC726E920247C258BE65FFCE5C0CD77F771B7B35DCB2885D29A187B71C8
HistoryNov 10, 2022 - 12:06 p.m.

Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Cognos Express (CVE-2014-4244, CVE-2014-4263)

2022-11-1012:06:25
www.ibm.com
13
ibm cognos express
ibm java runtime
vulnerabilities
cve-2014-4244
cve-2014-4263
security bulletin

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

EPSS

0.009

Percentile

82.5%

Summary

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition that is used by IBM Cognos Express. These issues were disclosed as part of the IBM Java SDK updates in July 2014.

Vulnerability Details

CVEID: CVE-2014-4263 DESCRIPTION: An unspecified vulnerability related to the Security component has partial confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/94606 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N)

CVEID: CVE-2014-4244 DESCRIPTION: An unspecified vulnerability related to the Security component has partial confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/94605 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N)

Affected Products and Versions

IBM Cognos Express 9.0

IBM Cognos Express 9.5

IBM Cognos Express 10.1

IBM Cognos Express 10.2.1

Remediation/Fixes

The recommended solution is to apply the fix in one of the IBM Cognos Express versions listed as soon as practical:

IBM Cognos Express 10.1 FP1
IBM Cognos Express 10.2.1 FP3

IBM Cognos Express 9.0 and 9.5 customers should upgrade to a more current version and apply the corresponding update. Please contact Customer Support with any questions.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmplanning_analyticsMatch9.0
OR
ibmplanning_analyticsMatch9.5
OR
ibmplanning_analyticsMatch10.1
OR
ibmplanning_analyticsMatch10.2.1
VendorProductVersionCPE
ibmplanning_analytics9.0cpe:2.3:a:ibm:planning_analytics:9.0:*:*:*:*:*:*:*
ibmplanning_analytics9.5cpe:2.3:a:ibm:planning_analytics:9.5:*:*:*:*:*:*:*
ibmplanning_analytics10.1cpe:2.3:a:ibm:planning_analytics:10.1:*:*:*:*:*:*:*
ibmplanning_analytics10.2.1cpe:2.3:a:ibm:planning_analytics:10.2.1:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

EPSS

0.009

Percentile

82.5%