CVE-2013-0501
IBM Cognos Disclosure Management 10.2.0 - RCE via EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX
Title source: llmDescription
The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/82345
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21627070
Scores
EPSS
0.0149
EPSS Percentile
71.4%
Details
CWE
CWE-264
Status
published
Products (1)
ibm/cognos_disclosure_management
10.2.0
Published
Apr 12, 2013
Tracked Since
Feb 18, 2026