PT-2013-2387 · Ibm+1 · Ibm Cognos Disclosure Management+1

Published

2013-04-12

·

Updated

2017-08-29

·

CVE-2013-0501

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Edraw Office Viewer Component version not specified IBM Cognos Disclosure Management (CDM) version 10.2.0
Description The issue allows remote attackers to read arbitrary files or download and execute an arbitrary program onto a client machine via a crafted web site. This is due to the vulnerable EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control used in the affected products.
Recommendations For IBM Cognos Disclosure Management (CDM) version 10.2.0, at the moment, there is no information about a newer version that contains a fix for this issue. For Edraw Office Viewer Component, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0501

Affected Products

Edraw Office Viewer
Ibm Cognos Disclosure Management