PT-2013-2387 · Ibm+1 · Ibm Cognos Disclosure Management+1

Publicado

2013-04-12

·

Atualizado

2017-08-29

·

CVE-2013-0501

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Edraw Office Viewer Component version not specified IBM Cognos Disclosure Management (CDM) version 10.2.0
Description The issue allows remote attackers to read arbitrary files or download and execute an arbitrary program onto a client machine via a crafted web site. This is due to the vulnerable EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control used in the affected products.
Recommendations For IBM Cognos Disclosure Management (CDM) version 10.2.0, at the moment, there is no information about a newer version that contains a fix for this issue. For Edraw Office Viewer Component, at the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-0501

Produtos afetados

Edraw Office Viewer
Ibm Cognos Disclosure Management