XPath Injection Vulnerability in IBM Cognos Business Intelligence
CVE-2012-4837

Currently unrated

Key Information:

Vendor

IBM

Vendor
CVE Published:
5 March 2013

What is CVE-2012-4837?

IBM Cognos Business Intelligence prior to specific fix releases is vulnerable to XPath injection attacks, enabling remote authenticated users to manipulate queries and access sensitive XML files. This can lead to unauthorized data exposure through exploited unspecified vectors, emphasizing the need for timely updates and proper security measures to safeguard against such threats.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.