Access Control Bypass in IBM Tivoli Common Reporting and Cognos Business Intelligence
CVE-2015-7436
2.5LOW
What is CVE-2015-7436?
In specific versions of IBM Tivoli Common Reporting and Cognos Business Intelligence, an access control bypass vulnerability exists due to the erroneous handling of user permissions during group-add and group-remove operations. This flaw permits local users to exploit administrative changes in group membership, potentially granting them unintended access to restricted resources. Proper security measures and timely updates are essential to mitigate risks associated with unauthorized access.