XML External Entity Vulnerability in IBM Cognos Business Intelligence
CVE-2014-0854
Currently unrated
Summary
The IBM Cognos Business Intelligence server versions 8.4.1 and multiple releases in the 10.x series exhibit a significant XML External Entity (XXE) vulnerability. This flaw allows remote authenticated users to exploit the server by submitting crafted XML documents. These documents may contain external entity declarations, enabling unauthorized access to sensitive files within the system. The resulting exposure puts confidential data at risk and can lead to further security breaches if not addressed.
References
Timeline
Vulnerability published
Vulnerability Reserved