Rewterz
Rewterz Threat Alert – Hidden Bee Malware Targeting Asia-Pacific Region
July 1, 2019
Rewterz
Rewterz Threat Alert – Agent Telsa Keylogger & NanoCore RAT Malware – Indicators of Compromise
July 1, 2019

Rewterz Threat Advisory – IBM Cognos TM1 Dojo Toolkit Script Insertion Vulnerability

Severity

High

Analysis summary

CVE-2018-15494, CVE-2019-4245
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/G=rid/DataGrid.

Impact

Cross Site Scripting

Affected Vendors

IBM

Affected Products

IBM Cognos TM1 10.x

Remediation

Update to version 10.2.2.7 Interim Fix 22.