CVE-2012-0696
Last modified
CVE-2012-0696 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to inject arbitrary web script or HTML via unspecified requests to (1) aspnet_client or (2) evserver/createcontrol.js.. EPSS estimates a 1.31% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to inject arbitrary web script or HTML via unspecified requests to (1) aspnet_client or (2) evserver/createcontrol.js.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Cognos Executive Viewer | All versions |
| Ibm | Cognos Tm1 | <= 9.4.1.3 |
| Ibm | Cognos Tm1 | 9.4.0 |
| Ibm | Cognos Tm1 | 9.4.1 |
References
- http://secunia.com/advisories/47487Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM26682Vendor Advisory
- http://secunia.com/advisories/47487Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM26682Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-0696?
How severe is CVE-2012-0696?
How do I fix CVE-2012-0696?
Are you affected by CVE-2012-0696?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
