CVE-2015-5014: IBM Cognos Disclosure Management
High severity, CVSS 9.3. EPSS: 1.5% chance of exploitation in the next 30 days.
IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an executable file during a client upload operation.
Affected products
- IBM Cognos Disclosure Management: version 10.2.0 only; version 10.2.1 only; version 10.2.2 only; version 10.2.3 only; version 10.2.4 only
Published 2015-10-26. Last modified 2026-06-17.