← Vulnerability feed

Vulnerability record · CVE-2013-0484 · published 19 June 2013

CVE-2013-0484: Ibm cognos tm1 vulnerability

Ibm · Cognos Tm1

The server process in IBM Cognos TM1 10.1.x before 10.1.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via an undocumented API call that triggers the transmission of unexpected data.

4.3 CVSS 2.0 Medium EPSS 1.1% · top 36.5%
4.3CVSS 2.0 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The server process in IBM Cognos TM1 10.1.x before 10.1.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via an undocumented API call that triggers the transmission of unexpected data.

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-0484 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-0202IBM Cognos TM1 Admin Server stack buffer overflow in tm1admsd.exeThe IBM Cognos TM1 Admin Server daemon (tm1admsd.exe) contains multiple stack-based buffer overflows in versions 9.4.x and 9.5.x before 9.5.2 FP2. Cr…EPSS 54%analysed6.1CVE-2017-1506Ibm cognos tm1 cross-site scripting vulnerabilityIBM Cognos TM1 10.2 and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…EPSS 1.1%5.0CVE-2014-0877Ibm cognos tm1 permissions and access controls vulnerabilityIBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restrictions by visiting the Rights page…EPSS 1.2%4.3CVE-2016-0381Ibm cognos tm1 improper input validation vulnerabilityIBM Cognos TM1 10.2.2 before FP5, when the host/pmhub/pm/admin AdminGroups setting is empty, allows remote authenticated users to cause a denial of s…EPSS 0.99%4.3CVE-2012-6350Ibm cognos tm1 cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the Web component in IBM Cognos TM1 before 9.5.2 FP3 and 10.1 before 10.1 FP1 allows remote attackers to …EPSS 0.93%4.3CVE-2012-1046Ibm cognos tm1 cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remote attackers to inject arbitrary web script or HTML via un…EPSS 1.3%4.3CVE-2012-0696Ibm cognos executive viewer cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to inject ar…EPSS 1.3%4.0CVE-2014-0863Ibm cognos tm1 vulnerabilityThe client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 stores obfuscated passwords in mem…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2013-0484), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.