The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.ibm.com/support/docview.wss?uid=swg21627070 | Vendor Advisory | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/82345 | 
Configurations
                    Information
                Published : 2013-04-12 12:55
Updated : 2017-08-28 18:33
NVD link : CVE-2013-0501
Mitre link : CVE-2013-0501
JSON object : View
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
Products Affected
                ibm
- cognos_disclosure_management
 


