SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-2978

Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than…

LOW 2.1EPSS 1.31%

Does this matter?

Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.

Description

Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CVE-2013-2988.

CVSS 2.0
2.1 LOWAV:N/AC:H/Au:S/C:P/I:N/A:N
EPSS
1.31% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
ibm/cognos business intelligence
Source
psirt@us.ibm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.