Cross-site Scripting Vulnerability in IBM Cognos 8 Business Intelligence
CVE-2011-0486

Currently unrated

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 January 2011

What is CVE-2011-0486?

A cross-site scripting (XSS) vulnerability exists in the cognos.cgi script of IBM Cognos 8 Business Intelligence versions prior to FP1. This vulnerability allows remote attackers to execute arbitrary web scripts or HTML by manipulating the pathinfo parameter. Successful exploitation could lead to unauthorized actions on behalf of users, potentially compromising sensitive data and system integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2011-0486 : Cross-site Scripting Vulnerability in IBM Cognos 8 Business Intelligence