CVE-2017-1125

IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
ibmcognos_business_intelligence_server
10.1.1
ibmcognos_business_intelligence_server
10.2.0
ibmcognos_business_intelligence_server
10.2.1
ibmcognos_business_intelligence_server
10.2.1.1
ibmcognos_business_intelligence_server
10.2.2
𝑥
= Vulnerable software versions