Cross-Site Scripting Vulnerability in IBM Cognos Business Intelligence
CVE-2017-1486
6.1MEDIUM
What is CVE-2017-1486?
IBM Cognos Business Intelligence versions 10.2 through 10.2.2 are susceptible to a cross-site scripting (XSS) vulnerability. This issue enables attackers to inject arbitrary JavaScript into the web interface, potentially altering features and leading to unauthorized disclosure of sensitive information, including user credentials during an established session. Security precautions should be taken to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cognos Business Intelligence 10.2
Cognos Business Intelligence 10.2.1
Cognos Business Intelligence 10.2.1.1
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved