IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.
History

Thu, 13 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm
Ibm cognos Analytics
CPEs cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Analytics
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-02-13T17:40:45.804Z

Reserved: 2024-02-03T14:49:33.094Z

Link: CVE-2024-25047

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:21.297Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-02T21:16:11.330

Modified: 2024-11-21T09:00:09.707

Link: CVE-2024-25047

cve-icon Redhat

No data.