CVE-2016-0221 Information

Description

Cross-site scripting (XSS) vulnerability in IBM Cognos TM1 as used in IBM Cognos Business Intelligence 10.2 before IF20 10.2.1 before IF17 10.2.1.1 before IF16 10.2.2 before IF12 and 10.1.1 before IF19 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Reference

http://www.securityfocus.com/bid/91542 http://www.securitytracker.com/id/1036221 http://www-01.ibm.com/support/docview.wss?uid=swg21984323

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

5.4

Share on: