Cross-Site Scripting Vulnerability in IBM Cognos Business Intelligence
CVE-2012-4836
Currently unrated
Summary
A cross-site scripting (XSS) vulnerability exists in IBM Cognos Business Intelligence products, allowing remote authenticated users to inject malicious web scripts or HTML. This occurs due to improper handling of crafted strings during the rendering of stored data. Affected versions include Cognos BI 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1. Attackers can exploit this vulnerability to execute arbitrary scripts in the context of the application, posing a significant risk to user data and system integrity.
References
Timeline
Vulnerability published
Vulnerability Reserved