CVE-2012-0202 is a critical vulnerability affecting IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2, specifically within the tm1admsd.exe Admin Server component. This flaw involves multiple stack-based buffer overflows that can be triggered remotely by unauthenticated attackers sending crafted data. With a CVSS score of 10.0, this vulnerability allows for a complete compromise, including denial of service (daemon crash) and potentially arbitrary code execution, requiring no user interaction. While not listed in CISA KEV, exploit code is publicly available through Metasploit and ExploitDB, indicating a high potential for exploitation despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.4.1CPE matchmatch criteria | cpe:2.3:a:ibm:cognos_tm1:9.4.1:*:*:*:*:*:*:* | ||
9.4.1.3CPE matchmatch criteria | cpe:2.3:a:ibm:cognos_tm1:9.4.1.3:*:*:*:*:*:*:* | ||
9.5.1CPE matchmatch criteria | cpe:2.3:a:ibm:cognos_tm1:9.5.1:*:*:*:*:*:*:* | ||
9.5.2CPE matchmatch criteria | cpe:2.3:a:ibm:cognos_tm1:9.5.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.