Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2024-31899

Disclosure Date: September 26, 2024 (last updated January 08, 2025)
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device.
Attacker Value
Unknown

CVE-2023-50324

Disclosure Date: March 01, 2024 (last updated March 01, 2024)
IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment to conduct further attacks. IBM X-Force ID: 275038.
0
Attacker Value
Unknown

CVE-2022-38707

Disclosure Date: May 05, 2023 (last updated February 24, 2025)
IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179.
Attacker Value
Unknown

CVE-2013-4000

Disclosure Date: December 14, 2013 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) start or (2) stop services.
0
Attacker Value
Unknown

CVE-2013-4001

Disclosure Date: December 14, 2013 (last updated October 05, 2023)
Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie.
0