CVE-2012-4836 Information

Description

Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1 10.1 before IF2 10.1.1 before IF2 and 10.2 before IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is not properly handled during rendering of stored data.

Reference

http://www-01.ibm.com/support/docview.wss?uid=swg21626697 http://www-01.ibm.com/support/docview.wss?uid=swg24034373 https://exchange.xforce.ibmcloud.com/vulnerabilities/78918

Share on: