CVE Published: 27/03/2017 |
CVE Updated: 06/08/2024 |
CVE Year: 2016 Source: ibm |
Vendor: IBM Corporation |
Product: Cognos Business Intelligence Status : PUBLISHED
CVE-2016-8960 Description
IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by intercepting the higher-privilege user\'s cookie value from its HTTP request and then reusing it in subsequent requests. IBM Reference #: 1993718.