Cross-Site Scripting Vulnerability in IBM Cognos Business Intelligence
CVE-2014-0861

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
22 February 2014

Summary

The vulnerability in IBM Cognos Business Intelligence allows remote attackers to exploit cross-site scripting (XSS) via an unspecified parameter that fails to be properly sanitized when the user navigates using the Back button. This mismanagement of parameters enables attackers to inject arbitrary web scripts or HTML, potentially compromising user sessions and facilitating further attacks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.