IBM Cognos Command Center 10.2.4.1 and 10.2.5
could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function.
Weakness
The product calls a function that can never be guaranteed to work safely.
Potential Mitigations
References