Lucene search

K
ibmIBMF229792BE5000C142C364B623BD73FFC6B890141B8F2D5D2C5A77242087AF95E
HistoryFeb 24, 2020 - 7:27 a.m.

Security Bulletin: A Security Vulnerability exist in IBM Cognos TM1

2020-02-2407:27:10
www.ibm.com
10

0.001 Low

EPSS

Percentile

44.9%

Summary

A vulnerability has been addressed for PM Hub config exposed via web interface

Vulnerability Details

CVEID: CVE-2016-0381**
DESCRIPTION:** IBM TM1 Cognos is vulnerable to a denial of service, caused by an administrator blanking-out a value called “AdminGroups” in the IBM Cognos Performance Management Hub configuration page at host/pmhub/pm/admin page under the security settings node. Once blanked-out, other users with knowledge of the URL can gain access to the configuration page, enter a non-blank value and prevent further access to the configuration.
CVSS Base Score: 3.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112247 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

  • IBM Cognos TM1 10.2.2

Remediation/Fixes

The recommended solution is to apply the fix for versions listed as soon as practical.

Cognos TM1 10.2.2 Fix Pack 5

Link: http://www-01.ibm.com/support/docview.wss?uid=swg24041747

Cognos TM1 10.2.2 FP5 IF1

Link: http://www.ibm.com/support/docview.wss?uid=swg24041902

CPENameOperatorVersion
cognos tm1eq10.2.2

0.001 Low

EPSS

Percentile

44.9%

Related for F229792BE5000C142C364B623BD73FFC6B890141B8F2D5D2C5A77242087AF95E