CVE-2016-0217

MEDIUM

IBM Cognos - XSS

Title source: llm

Description

IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

Scores

CVSS v3 5.4
EPSS 0.0016
EPSS Percentile 36.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status published

Affected Products (16)

ibm/cognos_analytics
ibm/cognos_analytics
ibm/cognos_analytics
ibm/cognos_analytics
ibm/cognos_analytics
IBM Corporation/Cognos Business Intelligence < 10
IBM Corporation/Cognos Business Intelligence < 8.3.0
IBM Corporation/Cognos Business Intelligence < 8.4.1
IBM Corporation/Cognos Business Intelligence < 8.4
IBM Corporation/Cognos Business Intelligence < 10.1
IBM Corporation/Cognos Business Intelligence < 10.1.1
IBM Corporation/Cognos Business Intelligence < 10.2
IBM Corporation/Cognos Business Intelligence < 10.2.1
IBM Corporation/Cognos Business Intelligence < 10.2.1.1
IBM Corporation/Cognos Business Intelligence < 10.2.2
... and 1 more

Timeline

Published Feb 01, 2017
Tracked Since Feb 18, 2026