Ibm Cognos Express vulnerabilities
4 known vulnerabilities affecting ibm/cognos_express.
Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2010-0557P3HIGHCVSS 7.5PoCv9.02010-02-05
CVE-2010-0557 [HIGH] CWE-255 CVE-2010-0557: IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials.
nvd
CVE-2013-5443P4MEDIUMCVSS 6.8v9.0v9.5+2 more2014-03-25
CVE-2013-5443 [MEDIUM] CWE-352 CVE-2013-5443: Cross-site request forgery (CSRF) vulnerability in IBM Cognos Express 9.0 before IFIX 2, 9.5 before
Cross-site request forgery (CSRF) vulnerability in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to hijack the authentication of arbitrary users.
nvd
CVE-2013-5444P4MEDIUMCVSS 5.0v9.0v9.5+2 more2014-03-25
CVE-2013-5444 [MEDIUM] CWE-310 CVE-2013-5444: The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.
The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encrypted credentials via unspecified vectors.
nvd
CVE-2013-5445P4MEDIUMCVSS 5.0v9.0v9.5+2 more2014-03-25
CVE-2013-5445 [MEDIUM] CWE-310 CVE-2013-5445: IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 a
IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext information by leveraging knowledge of a static decryption key.
nvd