CVE-2012-4836
Last modified
CVE-2012-4836 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is not properly handled during rendering of stored data.. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is not properly handled during rendering of stored data.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Cognos Business Intelligence | 8.4.1 |
| Ibm | Cognos Business Intelligence | 10.1 |
| Ibm | Cognos Business Intelligence | 10.1.1 |
| Ibm | Cognos Business Intelligence | 10.2 |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21626697Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg24034373Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21626697Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg24034373Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-4836?
How severe is CVE-2012-4836?
How do I fix CVE-2012-4836?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-4829IBM XIV Storage System Gen3 before 11.2 relies on a default …
- CVE-2012-4830Unspecified vulnerability in IBM WebSphere Commerce 6.0 thro…
- CVE-2012-4832Information Services Framework (ISF) in IBM InfoSphere Infor…
- CVE-2012-4833fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, …
- CVE-2012-4834Directory traversal vulnerability in LayerLoader.jsp in the …
- CVE-2012-4835Cross-site scripting (XSS) vulnerability in IBM Cognos Busin…
- CVE-2012-4837IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1…
- CVE-2012-4838IBM Flex System Chassis Management Module (CMM) and Integrat…
- CVE-2012-4839The OSLC interface in the Web Client (aka CQ Web) in IBM Rat…
- CVE-2012-4840IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1…
- CVE-2012-4841Unspecified vulnerability in Tivoli Endpoint Manager for Rem…
- CVE-2012-4842Open redirect vulnerability in the web server in IBM Lotus D…
Are you affected by CVE-2012-4836?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
