XPath Injection Vulnerability in IBM Cognos Business Intelligence
CVE-2012-4837
Currently unrated
What is CVE-2012-4837?
IBM Cognos Business Intelligence prior to specific fix releases is vulnerable to XPath injection attacks, enabling remote authenticated users to manipulate queries and access sensitive XML files. This can lead to unauthorized data exposure through exploited unspecified vectors, emphasizing the need for timely updates and proper security measures to safeguard against such threats.