CVE-2012-2177: IBM Cognos Business Intelligence
Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors related to the search feature.
Affected products
- IBM Cognos Business Intelligence: version 8.4.1 only; version 10.1 only; version 10.1.1 only; version 10.2 only
Published 2013-03-05. Last modified 2026-06-16.