Cognos Disclosure Management
by IBM
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-2413 | Med | 0.35 | 5.4 | 0.01 | Apr 10, 2018 | SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | ||
| CVE-2018-2403 | Med | 0.35 | 5.4 | 0.01 | Apr 10, 2018 | Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a specific chapter type to a chapter the user has not been given… | ||
| CVE-2016-6077 | Med | 0.35 | 5.3 | 0.01 | Feb 15, 2017 | IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user that opens a malicious document. IBM Reference #: 1991584. | ||
| CVE-2018-2404 | Med | 0.28 | 4.3 | 0.02 | Apr 10, 2018 | SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation. | ||
| CVE-2018-2412 | Low | 0.25 | 3.8 | 0.01 | Apr 10, 2018 | SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | ||
| CVE-2015-5014 | 0.00 | — | 0.01 | Oct 26, 2015 | IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an executable file during a client upload operation. | |||
| CVE-2013-0501 | 0.00 | — | 0.01 | Apr 12, 2013 | The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client… |
- risk 0.35cvss 5.4epss 0.01
SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
- risk 0.35cvss 5.4epss 0.01
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a specific chapter type to a chapter the user has not been given…
- risk 0.35cvss 5.3epss 0.01
IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user that opens a malicious document. IBM Reference #: 1991584.
- risk 0.28cvss 4.3epss 0.02
SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.
- risk 0.25cvss 3.8epss 0.01
SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
- CVE-2015-5014Oct 26, 2015risk 0.00cvss —epss 0.01
IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an executable file during a client upload operation.
- CVE-2013-0501Apr 12, 2013risk 0.00cvss —epss 0.01
The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client…