VulnerabilityModified
CVE-2012-0696
Multiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to inject arbitrary web script or HTML via unspecified requests to (1) aspnet_client or (2) evserver/createcontrol.js.
MEDIUM 4.3EPSS 1.26%
Does this matter?
Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to inject arbitrary web script or HTML via unspecified requests to (1) aspnet_client or (2) evserver/createcontrol.js.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/cognos executive viewer · ibm/cognos tm1
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/47487Vendor Advisory
- http://securitytracker.com/id?1026491
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM26682Vendor Advisory
- http://www.osvdb.org/78216
- http://www.osvdb.org/78217
- http://www.securityfocus.com/bid/51326
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72198
- http://secunia.com/advisories/47487Vendor Advisory
- http://securitytracker.com/id?1026491
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM26682Vendor Advisory
- http://www.osvdb.org/78216
- http://www.osvdb.org/78217
- http://www.securityfocus.com/bid/51326
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72198
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.