Multiple vulnerabilities in IBM Cognos Command Center

Published: 2017-11-08 17:35:50 | Updated: 2017-11-08 17:38:18
Severity High
Patch available YES
Number of vulnerabilities 2
CVSSv2 5.6 (AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.8 (AV:N/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
CVSSv3 7.2 [CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
6.5 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE ID CVE-2017-10116
CVE-2017-10115
CWE ID CWE-264
CWE-200
Exploitation vector Network
Public exploit Not available
Vulnerable software IBM Cognos Command Center
Vulnerable software versions IBM Cognos Command Center 10.2.4
Vendor URL IBM Corporation
Advisory type Public

Security Advisory

1) Remote code execution

Description

The vulnerability allows a remote authenticated attacker to execute arbitrary code.

The weakness exists due to unknown error. A remote attacker can trick the victim into visiting a specially crafted website, execute arbitrary code with elevated privileges and take full control over the system.

Remediation

Install update from vendor's website.

External links

http://www-01.ibm.com/support/docview.wss?uid=swg22009304&myns=swgimgmt&mynp=OCSSPLNP&mync=E&cm_sp=swgimgmt-_-OCSSPLNP-_-E

2) Information disclosure

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The weakness exists due to unknown error. A remote attacker can disclose important data on the target system

Remediation

Install update from vendor's website.

External links

http://www-01.ibm.com/support/docview.wss?uid=swg22009304&myns=swgimgmt&mynp=OCSSPLNP&mync=E&cm_sp=swgimgmt-_-OCSSPLNP-_-E

Back to List