PT-2017-7599 · Ibm · Ibm Cognos Business Intelligence
Jakub Palaczynski
·
Published
2017-06-07
·
Updated
2017-06-14
·
CVE-2016-0254
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
IBM Cognos Business Intelligence versions 10.1 through 10.2
Description
The issue is caused by an XML External Entity Injection (XXE) error when processing XML data, allowing a remote authenticated attacker to consume all available CPU resources and cause a denial of service.
Recommendations
For versions 10.1 and 10.2, consider restricting access to XML data processing until a fix is available.
As a temporary workaround, limit the CPU resources available to the application to prevent complete consumption.
Avoid using the XML processing feature in the affected versions until the issue is resolved.
Fix
DoS
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Cognos Business Intelligence