CVE-2014-4810

IBM Cognos Mobile 10.1.1 before FP3 IF1, 10.2.0 before FP2 IF1, and 10.2.1 before FP4 IF1 preserves a session between the Cognos Mobile server and the Cognos Business Intelligence server after a logoff action on a mobile device, which makes it easier for remote attackers to bypass intended Business Intelligence restrictions by leveraging access to authentication data that was captured before this logoff.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:cognos_mobile:10.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_mobile:10.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_mobile:10.2.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-11-05 11:55

Updated : 2024-02-28 12:20


NVD link : CVE-2014-4810

Mitre link : CVE-2014-4810

CVE.ORG link : CVE-2014-4810


JSON object : View

Products Affected

ibm

  • cognos_mobile
CWE
CWE-264

Permissions, Privileges, and Access Controls