← Vulnerability feed

Vulnerability record · CVE-2012-0202 · published 4 May 2012

CVE-2012-0202: IBM Cognos TM1 Admin Server stack buffer overflow in tm1admsd.exe

Ibm · Cognos Tm1

The IBM Cognos TM1 Admin Server daemon (tm1admsd.exe) contains multiple stack-based buffer overflows in versions 9.4.x and 9.5.x before 9.5.2 FP2. Crafted data sent to the daemon can crash it or potentially allow arbitrary code execution. Because the service is network-reachable and needs no credentials, it is a serious exposure for any unpatched TM1 deployment.

10.0 CVSS 2.0 High EPSS 54% · top 1.0% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted data.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable memory corruption with CVSS 10 and high EPSS, though no confirmed in-the-wild exploitation or KEV listing.

What it is

The IBM Cognos TM1 Admin Server daemon (tm1admsd.exe) contains multiple stack-based buffer overflows in versions 9.4.x and 9.5.x before 9.5.2 FP2. Crafted data sent to the daemon can crash it or potentially allow arbitrary code execution. Because the service is network-reachable and needs no credentials, it is a serious exposure for any unpatched TM1 deployment.

Impact

An unauthenticated remote attacker can crash the Admin Server daemon, causing denial of service, and may be able to execute arbitrary code in the context of the service.

Attack surface

Reached over the network via the Admin Server service (AV:N, AC:L, Au:N), with no authentication or user interaction required. The description does not specify the exact port or protocol, only that crafted data is sent to tm1admsd.exe.

Exploitation

Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is high (0.54467, ~99th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade IBM Cognos TM1 to 9.5.2 FP2 or later, or apply the vendor fix referenced in IBM advisories swg21590314 and swg24032164/32165/32166.
  • If patching cannot be done immediately, restrict network access to the Admin Server port to trusted management hosts only.
  • Run tm1admsd.exe with least privilege and isolate the TM1 Admin Server from general user networks.
  • Monitor IBM advisories for updated fixes and confirm the installed TM1 build level.
  • Retire or migrate end-of-life TM1 9.4.x/9.5.x installations where feasible.

Detection

  • Monitor tm1admsd.exe for crash events or unexpected process termination in Windows event logs.
  • Alert on network connections to the TM1 Admin Server port from untrusted or unexpected source addresses.
  • Look for anomalous or oversized payloads directed at the Admin Server service in network traffic.
  • Correlate repeated service restarts of tm1admsd.exe with inbound connection attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-0202 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2017-1506Ibm cognos tm1 cross-site scripting vulnerabilityIBM Cognos TM1 10.2 and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…EPSS 1.1%5.0CVE-2014-0877Ibm cognos tm1 permissions and access controls vulnerabilityIBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restrictions by visiting the Rights page…EPSS 1.2%4.3CVE-2016-0381Ibm cognos tm1 improper input validation vulnerabilityIBM Cognos TM1 10.2.2 before FP5, when the host/pmhub/pm/admin AdminGroups setting is empty, allows remote authenticated users to cause a denial of s…EPSS 0.99%4.3CVE-2013-0484Ibm cognos tm1 vulnerabilityThe server process in IBM Cognos TM1 10.1.x before 10.1.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via an undocumented…EPSS 1.1%4.3CVE-2012-6350Ibm cognos tm1 cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the Web component in IBM Cognos TM1 before 9.5.2 FP3 and 10.1 before 10.1 FP1 allows remote attackers to …EPSS 0.93%4.3CVE-2012-1046Ibm cognos tm1 cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remote attackers to inject arbitrary web script or HTML via un…EPSS 1.3%4.3CVE-2012-0696Ibm cognos executive viewer cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to inject ar…EPSS 1.3%4.0CVE-2014-0863Ibm cognos tm1 vulnerabilityThe client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 stores obfuscated passwords in mem…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2012-0202), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.