CVE-2017-1125

low
Published 2017-06-07 · Modified 2026-05-13
CVSS v3
3.3
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v2
2.1
VIR risk
3.3

Description

IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.

Predictions

Exploit likelihood
34%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — https://exchange.xforce.ibmcloud.com/vulnerabilities/121340

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg22004036

Application impact

VendorProductVersionsFixed
ibmcognos_business_intelligence_server10.1.1
ibmcognos_business_intelligence_server10.2.0
ibmcognos_business_intelligence_server10.2.1
ibmcognos_business_intelligence_server10.2.1.1
ibmcognos_business_intelligence_server10.2.2

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.