Flash (Alert)
Abstract
A malicious IBM Cognos BI 8.4 user is able to send a crafted request to the Cognos server which triggers high CPU utilization that may cause a partial denial of service condition due to CPU consumption. This vulnerability can only be exploited by authenticated users, and is not applicable to IBM Cognos BI 10.1 and later versions.
Content
DESCRIPTION: The partial denial of service condition is temporary and does not block other users from accessing the Cognos application.
CVE ID: CVE-2012-4847
CVSS: 4
AFFECTED PLATFORMS: IBM Cognos BI version 8.4 and 8.4.1
REMEDIATION: Upgrade to IBM BI version 10.1 or later.
WORKAROUND: Disable anonymous access to prevent unauthenticated users to access the vulnerable URL.
ACKNOWLEDGEMENT: This vulnerability was reported to IBM by Niv Sela, Hacktics ASC, Ernst & Young.
Rate this page:
Copyright and trademark information
IBM, the IBM logo and ibm.com are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the Web at "Copyright and trademark information" at www.ibm.com/legal/copytrade.shtml.