CVE-2013-0501

IBM Cognos Disclosure Management 10.2.0 - RCE via EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX

Title source: llm
STIX 2.1

Description

The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/82345
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21627070

Scores

EPSS 0.0149
EPSS Percentile 71.4%

Details

CWE
CWE-264
Status published
Products (1)
ibm/cognos_disclosure_management 10.2.0
Published Apr 12, 2013
Tracked Since Feb 18, 2026