CVE-2016-8960Corporation Cognos Business Intelligence vulnerability

CWE-2643 documents3 sources
Severity
8.8HIGHNVD
EPSS
0.5%
top 32.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateMay 17

Description

IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by intercepting the higher-privilege user's cookie value from its HTTP request and then reusing it in subsequent requests. IBM Reference #: 1993718.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vxjm-8m57-p725: IBM Cognos Business Intelligence 102022-05-17
CVEList
CVE-2016-8960: IBM Cognos Business Intelligence 102017-03-27
CVE-2016-8960 — HIGH severity | cvebase