IBM Cognos Controller 11.0.0 and 11.0.1
could allow an authenticated user to upload insecure files, due to insufficient file type distinction.
The product does not properly distinguish between different types of elements in a way that leads to insecure behavior.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cognos_controller | Ibm | 11.0.0 (including) | 11.0.0 (including) |
Cognos_controller | Ibm | 11.0.1 (including) | 11.0.1 (including) |