CVE-2013-5445

IBM Cognos Express <10.2.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext information by leveraging knowledge of a static decryption key.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/87821
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21667626

Scores

EPSS 0.0118
EPSS Percentile 64.5%

Details

CWE
CWE-310
Status published
Products (4)
ibm/cognos_express 9.0
ibm/cognos_express 9.5
ibm/cognos_express 10.1
ibm/cognos_express 10.2.1
Published Mar 25, 2014
Tracked Since Feb 18, 2026