Vulnerability record · CVE-2012-0202 · published 4 May 2012
CVE-2012-0202: IBM Cognos TM1 Admin Server stack buffer overflow in tm1admsd.exe
Ibm · Cognos Tm1
The IBM Cognos TM1 Admin Server daemon (tm1admsd.exe) contains multiple stack-based buffer overflows in versions 9.4.x and 9.5.x before 9.5.2 FP2. Crafted data sent to the daemon can crash it or potentially allow arbitrary code execution. Because the service is network-reachable and needs no credentials, it is a serious exposure for any unpatched TM1 deployment.
Description
Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted data.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityUnauthenticated network-reachable memory corruption with CVSS 10 and high EPSS, though no confirmed in-the-wild exploitation or KEV listing.
What it is
The IBM Cognos TM1 Admin Server daemon (tm1admsd.exe) contains multiple stack-based buffer overflows in versions 9.4.x and 9.5.x before 9.5.2 FP2. Crafted data sent to the daemon can crash it or potentially allow arbitrary code execution. Because the service is network-reachable and needs no credentials, it is a serious exposure for any unpatched TM1 deployment.
Impact
An unauthenticated remote attacker can crash the Admin Server daemon, causing denial of service, and may be able to execute arbitrary code in the context of the service.
Attack surface
Reached over the network via the Admin Server service (AV:N, AC:L, Au:N), with no authentication or user interaction required. The description does not specify the exact port or protocol, only that crafted data is sent to tm1admsd.exe.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is high (0.54467, ~99th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade IBM Cognos TM1 to 9.5.2 FP2 or later, or apply the vendor fix referenced in IBM advisories swg21590314 and swg24032164/32165/32166.
- If patching cannot be done immediately, restrict network access to the Admin Server port to trusted management hosts only.
- Run tm1admsd.exe with least privilege and isolate the TM1 Admin Server from general user networks.
- Monitor IBM advisories for updated fixes and confirm the installed TM1 build level.
- Retire or migrate end-of-life TM1 9.4.x/9.5.x installations where feasible.
Detection
- Monitor tm1admsd.exe for crash events or unexpected process termination in Windows event logs.
- Alert on network connections to the TM1 Admin Server port from untrusted or unexpected source addresses.
- Look for anomalous or oversized payloads directed at the Admin Server service in network traffic.
- Correlate repeated service restarts of tm1admsd.exe with inbound connection attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-0202 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-0202), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.