CVE-2013-0501: IBM Cognos Disclosure Management

High severity, CVSS 9.3. EPSS: 1.5% chance of exploitation in the next 30 days.

The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.

Affected products

  • IBM Cognos Disclosure Management: version 10.2.0 only

Published 2013-04-12. Last modified 2026-06-16.