VYPR
Medium severity6.5NVD Advisory· Published Jun 7, 2017· Updated May 13, 2026

CVE-2016-0254

CVE-2016-0254

Description

IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote authenticated attacker could exploit this vulnerability to consume all available CPU resources and cause a denial of service. IBM X-Force ID: 110563.

Affected products

1
  • IBM/Cognos Business Intelligencev5
    Range: 10.1.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.