CVE-2011-0486
Description
Cross-site scripting (XSS) vulnerability in cognos.cgi in IBM Cognos 8 Business Intelligence (BI) 8.4.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via the pathinfo parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Cognos 8 BI 8.4.1 before FP1 is vulnerable to reflected XSS in cognos.cgi via the pathinfo parameter, enabling arbitrary script injection.
Vulnerability
A cross-site scripting (XSS) vulnerability exists in cognos.cgi, part of IBM Cognos 8 Business Intelligence (BI) version 8.4.1 prior to Fix Pack 1 (FP1). The flaw resides in the handling of the pathinfo parameter, which is echoed back without proper sanitization, allowing injection of arbitrary HTML and JavaScript. Affected versions are all releases of IBM Cognos 8 BI 8.4.1 before the application of FP1 [1].
Exploitation
Exploitation does not require authentication as cognos.cgi is publicly accessible. An attacker can craft a malicious URL containing the pathinfo parameter with embedded script code and trick a victim into clicking it (e.g., via email or a phishing link). No special network position or user interaction beyond clicking the link is needed. The reflected XSS executes in the context of the victim's session with the application.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser within the security context of the IBM Cognos 8 BI domain. This leads to potential session hijacking, defacement, or theft of sensitive data displayed by the application. The attacker gains the same access privileges as the targeted user.
Mitigation
IBM released Fix Pack 1 (FP1) for Cognos 8 BI 8.4.1, which addresses this vulnerability [1]. All users should upgrade to 8.4.1 FP1 or later. No workarounds are documented. This CVE is not listed on the Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2cpe:2.3:a:ibm:cognos_8_business_intelligence:8.4.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:cognos_8_business_intelligence:8.4.1:*:*:*:*:*:*:*
- (no CPE)range: <8.4.1 FP1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7News mentions
0No linked articles in our index yet.