VendorsIBMcognos_disclosure_management10.2.0
Vulnerabilities

IBM Cognos Disclosure Management (CDM) 10.2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2013-0501
The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.
Published 2013-04-12 · Modified
9.3EPSS 0.015
CVE-2015-5014
IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an executable file during a client upload operation.
Published 2015-10-26 · Modified
9.3EPSS 0.015
CVE-2016-6077
IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user that opens a malicious document. IBM Reference #: 1991584.
Published 2017-02-15 · Modified
6.8EPSS 0.007