Cross-Site Scripting in IBM Cognos Business Intelligence & Analytics
CVE-2016-0218
Key Information:
- Vendor
IBM Corporation
- Vendor
- CVE Published:
- 1 February 2017
What is CVE-2016-0218?
IBM Cognos Business Intelligence and IBM Cognos Analytics are affected by a cross-site scripting vulnerability. This issue arises from improper validation of user-supplied input, allowing remote attackers to exploit it using specially-crafted URLs. By clicking the malicious link, a victim can unwittingly execute scripts in their web browser within the security context of the hosting website. An attacker can leverage this vulnerability to extract cookie-based authentication credentials, posing significant security risks to users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cognos Business Intelligence 10
Cognos Business Intelligence 8.3.0
Cognos Business Intelligence 8.4.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved