Cross-site Scripting Vulnerability in IBM Cognos 8 Business Intelligence
CVE-2011-0486
Currently unrated
What is CVE-2011-0486?
A cross-site scripting (XSS) vulnerability exists in the cognos.cgi script of IBM Cognos 8 Business Intelligence versions prior to FP1. This vulnerability allows remote attackers to execute arbitrary web scripts or HTML by manipulating the pathinfo parameter. Successful exploitation could lead to unauthorized actions on behalf of users, potentially compromising sensitive data and system integrity.