Security Bulletin
Summary
IBM Cognos Business Intelligence is shipped as a component of IBM Cognos Controller. Information about a security vulnerability affecting IBM Cognos Business Intelligence has been published in a security bulletin.
Vulnerability Details
Please consult the Security Bulletin: IBM Cognos BI Server is affected by the following OpenSSL vulnerability: CVE-2014-0224 for vulnerability details.
Affected Products and Versions
|
Principal Product and Version(s) | Affected Supporting Product and Version |
| IBM Cognos Controller 10.2.0.x IBM Cognos Controller 10.1.1.x IBM Cognos Controller 10.1.x IBM Cognos Controller 8.5.1.x | IBM Cognos Business Intelligence 10.2.1.2 IBM Cognos Business Intelligence 10.1.1 IBM Cognos Business Intelligence 10.1 IBM Cognos Business Intelligence 8.4.1 |
Remediation/Fixes
Download the fix for the corresponding version of IBM Cognos Business intelligence and apply the fix on top of your IBM Cognos Controller installation. The fix will update the necessary files without affecting IBM Cognos Controller.
Note: The installation of the fix for IBM Cognos Controller 10.2.0.x has a prerequisite. When you apply the fix to IBM Cognos Controller 10.2.0.x you must first download and install the IBM Cognos Business Intelligence 10.2.1.2 Fix Pack.
Get Notified about Future Security Bulletins
References
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
15 June 2018
UID
swg21680022