Stored Cross-Site Scripting Vulnerability in IBM Cognos Products
CVE-2016-0217
Key Information:
- Vendor
IBM Corporation
- Vendor
- CVE Published:
- 1 February 2017
What is CVE-2016-0217?
IBM Cognos Business Intelligence and IBM Cognos Analytics have a vulnerability that allows for stored cross-site scripting due to inadequate validation of user-supplied input. This weakness can enable a remote attacker to inject malicious scripts into a web page, which, when accessed by a victim, executes within the context of the hosting site. Exploitation of this vulnerability can lead to the theft of cookie-based authentication credentials, posing significant risks to user security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cognos Business Intelligence 10
Cognos Business Intelligence 8.3.0
Cognos Business Intelligence 8.4.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved