VYPR
Unrated severityNVD Advisory· Published Aug 27, 2013· Updated Apr 29, 2026

CVE-2013-2978

CVE-2013-2978

Description

Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CVE-2013-2988.

Affected products

5
  • cpe:2.3:a:ibm:cognos_business_intelligence:8.4.1:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:ibm:cognos_business_intelligence:8.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:cognos_business_intelligence:10.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:cognos_business_intelligence:10.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:cognos_business_intelligence:10.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.