PT-2017-7599 · Ibm · Ibm Cognos Business Intelligence

Jakub Palaczynski

·

Published

2017-06-07

·

Updated

2017-06-14

·

CVE-2016-0254

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions IBM Cognos Business Intelligence versions 10.1 through 10.2
Description The issue is caused by an XML External Entity Injection (XXE) error when processing XML data, allowing a remote authenticated attacker to consume all available CPU resources and cause a denial of service.
Recommendations For versions 10.1 and 10.2, consider restricting access to XML data processing until a fix is available. As a temporary workaround, limit the CPU resources available to the application to prevent complete consumption. Avoid using the XML processing feature in the affected versions until the issue is resolved.

Fix

DoS

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-0254

Affected Products

Ibm Cognos Business Intelligence