XML External Entity Vulnerability in IBM Cognos Business Intelligence
CVE-2014-0854

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
22 February 2014

Summary

The IBM Cognos Business Intelligence server versions 8.4.1 and multiple releases in the 10.x series exhibit a significant XML External Entity (XXE) vulnerability. This flaw allows remote authenticated users to exploit the server by submitting crafted XML documents. These documents may contain external entity declarations, enabling unauthorized access to sensitive files within the system. The resulting exposure puts confidential data at risk and can lead to further security breaches if not addressed.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.