IBM Support

Security Bulletin: A security vulnerability has been identified in IBM Cognos Business Intelligence shipped with IBM Cognos Controller 8.5.1.x, 10.1.x. 10.1.1.x, and 10.2.0.x (CVE-2014-0224).

Created by Marco Maas on
Published URL:
https://www.ibm.com/support/pages/node/245855
245855

Security Bulletin


Summary

IBM Cognos Business Intelligence is shipped as a component of IBM Cognos Controller. Information about a security vulnerability affecting IBM Cognos Business Intelligence has been published in a security bulletin.

Vulnerability Details

Please consult the Security Bulletin: IBM Cognos BI Server is affected by the following OpenSSL vulnerability: CVE-2014-0224 for vulnerability details.

Affected Products and Versions

Principal Product and Version(s)

Affected Supporting Product and Version
IBM Cognos Controller 10.2.0.x
IBM Cognos Controller 10.1.1.x
IBM Cognos Controller 10.1.x
IBM Cognos Controller 8.5.1.x
IBM Cognos Business Intelligence 10.2.1.2
IBM Cognos Business Intelligence 10.1.1
IBM Cognos Business Intelligence 10.1
IBM Cognos Business Intelligence 8.4.1

Remediation/Fixes

Download the fix for the corresponding version of IBM Cognos Business intelligence and apply the fix on top of your IBM Cognos Controller installation. The fix will update the necessary files without affecting IBM Cognos Controller.

Note: The installation of the fix for IBM Cognos Controller 10.2.0.x has a prerequisite. When you apply the fix to IBM Cognos Controller 10.2.0.x you must first download and install the IBM Cognos Business Intelligence 10.2.1.2 Fix Pack.

Get Notified about Future Security Bulletins

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SS9S6B","label":"IBM Cognos Controller"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Controller","Platform":[{"code":"PF033","label":"Windows"}],"Version":"10.2.0;10.1.1;10.1;8.5.1","Edition":"All Editions","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
15 June 2018

UID

swg21680022