Description
The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encrypted credentials via unspecified vectors.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21667626
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/87820
Scores
EPSS
0.0167
EPSS Percentile
74.3%
Details
CWE
CWE-310
Status
published
Products (4)
ibm/cognos_express
9.0
ibm/cognos_express
9.5
ibm/cognos_express
10.1
ibm/cognos_express
10.2.1
Published
Mar 25, 2014
Tracked Since
Feb 18, 2026