CVE-2017-1125

IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
ibmCNA
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
Affected Products (NVD)
VendorProductVersion
ibmcognos_business_intelligence_server
10.1.1
ibmcognos_business_intelligence_server
10.2.0
ibmcognos_business_intelligence_server
10.2.1
ibmcognos_business_intelligence_server
10.2.1.1
ibmcognos_business_intelligence_server
10.2.2
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
ibmcognos_business_intelligence
10.1.1
CNA
ibmcognos_business_intelligence
10.2
CNA
ibmcognos_business_intelligence
10.2.1
CNA
ibmcognos_business_intelligence
10.2.1.1
CNA
ibmcognos_business_intelligence
10.2.2
CNA