Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) start or (2) stop services.
| Software | From | Fixed in |
|---|---|---|
| ibm / cognos_command_center | 10.0 | 10.0.x |
| ibm / cognos_command_center | - | 10.1.x |