Privilege Escalation in IBM Cognos Business Intelligence
CVE-2016-8960
What is CVE-2016-8960?
IBM Cognos Business Intelligence 10.2 is susceptible to a privilege escalation vulnerability, which allows lower-privilege users to gain elevated access. This occurs when an attacker intercepts the cookie value of a high-privilege user during an HTTP request. By reusing this cookie in their own requests, the low-privilege user can adopt the permissions of the higher-privilege user, potentially leading to unauthorized actions within the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cognos Business Intelligence 10.2
Cognos Business Intelligence 10.2.1
Cognos Business Intelligence 10.2.1.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved