IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the My schedules and subscriptions page is visible and accessible to a less privileged user. IBM X-Force ID: 167449.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cognos_analytics | Ibm | 11.0.0 (including) | 11.0.0 (including) |
Cognos_analytics | Ibm | 11.1.0 (including) | 11.1.0 (including) |