Show plain JSON{"id": "CVE-2012-4840", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2013-03-05T05:02:08.583", "references": [{"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21626697", "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg24034373", "source": "psirt@us.ibm.com"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/79116", "source": "psirt@us.ibm.com"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-94"}]}], "descriptions": [{"lang": "en", "value": "IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XPath injection attacks, and call XPath extension functions, via unspecified vectors."}, {"lang": "es", "value": "IBM Cognos Business Intelligence (BI) 8.4.1 antes de IF1, IF2 v10,1 antes, antes IF2 v10.1.1, y v10.2 antes de IF1 permite a atacantes remotos para realizar ataques de inyecci\u00f3n XPath, y llamar a funciones de extensiones de XPath, a trav\u00e9s de vectores no especificados."}], "lastModified": "2017-08-29T01:32:23.133", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:8.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B76A06D-761D-4CFE-A9E6-FC5A1F726CF5"}, {"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "519B7097-7E46-4520-B9F9-A85E13A0F9CE"}, {"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B00BAD84-4BB6-41ED-835E-86AB150716D9"}, {"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6588FEE1-5A6F-4ED6-998A-B8CF54954F5D"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}