« Volver al listado

CVE-2014-0861

Estado: ModificadaBaja (3.5)—

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled during use of the Back button.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-0861",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-02-22T21:55:09.877",
  "references": [
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21662856",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21662856",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled during use of the Back button."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de tipo cross-site scripting (XSS) en el servidor en Cognos Business Intelligence (BI) de IBM versión 8.4.1, versión 10.1 anterior a IF6, versión 10.1.1 anterior a IF5, versión 10.2 anterior a IF7, versión 10.2.1 anterior a IF4, y versión 10.2.1.1 anterior a IF4, permite a los atacantes remotos inyectar script web o HTML arbitrario por medio de un parámetro no especificado que no es manejado apropiadamente durante el uso del botón Back."
    }
  ],
  "lastModified": "2026-06-17T00:03:44.910",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:8.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B76A06D-761D-4CFE-A9E6-FC5A1F726CF5"
            },
            {
              "criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "519B7097-7E46-4520-B9F9-A85E13A0F9CE"
            },
            {
              "criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B00BAD84-4BB6-41ED-835E-86AB150716D9"
            },
            {
              "criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6588FEE1-5A6F-4ED6-998A-B8CF54954F5D"
            },
            {
              "criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDA8132D-A09E-4D4C-9A5D-D708010CCFFD"
            },
            {
              "criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CCBB0AE-ECD1-4192-B1BB-18439A4CF7B9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}