CVE-2015-1969
Cross-site scripting (XSS) vulnerability in IBM Tivoli Common Reporting (TCR) 2.1 before IF13 and 2.1.1 before IF21, and TCR 3.1.x as used in Cognos Business Intelligence before 10.2 IF0015 and other products, allows remote authenticated users to inject…
Does this matter?
Lower severity and a low EPSS score (1.46%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in IBM Tivoli Common Reporting (TCR) 2.1 before IF13 and 2.1.1 before IF21, and TCR 3.1.x as used in Cognos Business Intelligence before 10.2 IF0015 and other products, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 1.46% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/tivoli common reporting
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21967384Patch, Vendor Advisory
- http://www.securityfocus.com/bid/76472
- http://www.securitytracker.com/id/1034050
- http://www-01.ibm.com/support/docview.wss?uid=swg21967384Patch, Vendor Advisory
- http://www.securityfocus.com/bid/76472
- http://www.securitytracker.com/id/1034050
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.