Vulnerability Bulletins

IBM Security Bulletin: Cognos Disclosure Management file upload bypass (CVE-2015-5014)

   
Affected software IBM
 
A specific usage scenario of IBM Cognos Disclosure Management could allow a remote attacker to obtain sensitive information. An attacker could send a specially crafted executable file to a CDM client machine by using a man-in-the-middle mechanism. CVE(s): CVE-2015-5014 Affected product(s) and affected version(s): Cognos Disclosure Management 10.2.4 and previous Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_cognos_disclosure_management_file_upload_bypass_cve_2015_5014?lang=en_us