CVE-2015-1969
Summary
| CVE | CVE-2015-1969 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-10-04 02:59:00 UTC |
| Updated | 2016-12-07 18:09:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in IBM Tivoli Common Reporting (TCR) 2.1 before IF13 and 2.1.1 before IF21, and TCR 3.1.x as used in Cognos Business Intelligence before 10.2 IF0015 and other products, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Tivoli Common Reporting | 2.1.0.0 | All | All | All |
| Application | Ibm | Tivoli Common Reporting | 2.1.1.0 | All | All | All |
| Application | Ibm | Tivoli Common Reporting | 3.1.0.0 | All | All | All |
| Application | Ibm | Tivoli Common Reporting | 3.1.0.1 | All | All | All |
| Application | Ibm | Tivoli Common Reporting | 3.1.0.2 | All | All | All |
| Application | Ibm | Tivoli Common Reporting | 3.1.2 | All | All | All |
| Application | Ibm | Tivoli Common Reporting | 2.1.0.0 | All | All | All |
| Application | Ibm | Tivoli Common Reporting | 2.1.1.0 | All | All | All |
| Application | Ibm | Tivoli Common Reporting | 3.1.0.0 | All | All | All |
| Application | Ibm | Tivoli Common Reporting | 3.1.0.1 | All | All | All |
| Application | Ibm | Tivoli Common Reporting | 3.1.0.2 | All | All | All |
| Application | Ibm | Tivoli Common Reporting | 3.1.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Cognos Business Intelligence Server CVE-2015-1969 Unspecified Cross Site Scripting Vulnerability | BID | www.securityfocus.com | |
| IBM Security Bulletin: Multiple vulnerability in Product IBM Tivoli Common Reporting (CVE-2014-0230, CVE-2015-4000, CVE-2015-1969, CVE-2015-1789, CVE-2015-1790, CVE-2015-1792, CVE-2015-2625, CVE-2015-4748, CVE-2015-4749) - United States | CONFIRM | www-01.ibm.com | Patch, Vendor Advisory |
| IBM Tivoli Common Reporting Input Validation Flaw Lets Remote Conduct Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.