VYPR
Unrated severityNVD Advisory· Published Feb 22, 2014· Updated Jun 17, 2026

CVE-2014-0861

CVE-2014-0861

Description

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled during use of the Back button.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • cpe:2.3:a:ibm:cognos_business_intelligence:10.1:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:ibm:cognos_business_intelligence:10.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:cognos_business_intelligence:10.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:cognos_business_intelligence:10.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:cognos_business_intelligence:8.4.1:*:*:*:*:*:*:*
    • (no CPE)range: 8.4.1, 10.1 < IF6, 10.1.1 < IF5, 10.2 < IF7, 10.2.1 < IF4, 10.2.1.1 < IF4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.