CVE-2013-4034
IBM Cognos Business Intelligence - Access Control
Title source: ruleDescription
IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Exploits (1)
Scores
EPSS
0.0873
EPSS Percentile
92.5%
Details
CWE
CWE-264
Status
published
Products (6)
ibm/cognos_business_intelligence
8.4.1
ibm/cognos_business_intelligence
10.1
ibm/cognos_business_intelligence
10.1.1
ibm/cognos_business_intelligence
10.2
ibm/cognos_business_intelligence
10.2.1
ibm/cognos_business_intelligence
10.2.1.1
Published
Nov 18, 2013
Tracked Since
Feb 18, 2026