IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176610.
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cognos_analytics | Ibm | 11.0.0 (including) | 11.0.13 (excluding) |
Cognos_analytics | Ibm | 11.1.0 (including) | 11.1.7 (including) |
Cognos_analytics | Ibm | 11.0.13 (including) | 11.0.13 (including) |
Cognos_analytics | Ibm | 11.0.13-fixpack1 (including) | 11.0.13-fixpack1 (including) |
Cognos_analytics | Ibm | 11.0.13-fixpack2 (including) | 11.0.13-fixpack2 (including) |