CVE-2013-4034 EXPLOIT
4.0
MEDIUM · CVSS 2.0 · EPSS 5.6% (pctl 93)
Patch early
A public exploit exists.
Description
IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Scoring
| CVSS | 4.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
| EPSS | 5.56% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-11-18 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ibm | cognos business intelligence |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IBM Cognos Business Intelligence - XML External Entity Information Disclosure | 2013-10-11 |
References
→ the Explorer · watch your stack · NVD