CVE-2014-0877

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
05/09/2014
Last modified:
12/04/2025

Description

IBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restrictions by visiting the Rights page and then following a generated link.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:cognos_tm1:10.2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_tm1:10.2.2.0:*:*:*:*:*:*:*