IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Feb 2025 16:30:00 +0000

Type Values Removed Values Added
Title IBM MQ path traversal IBM Cognos Analytics path traversal

Fri, 28 Feb 2025 02:45:00 +0000

Type Values Removed Values Added
Description IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
Title IBM MQ path traversal
First Time appeared Ibm
Ibm cognos Analytics
Weaknesses CWE-23
CPEs cpe:2.3:a:ibm:cognos_analytics:11.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.4:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Analytics
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-02-28T02:32:30.345Z

Updated: 2025-02-28T16:15:40.732Z

Reserved: 2024-12-20T13:55:07.212Z

Link: CVE-2024-56340

cve-icon Vulnrichment

Updated: 2025-02-28T16:03:49.500Z

cve-icon NVD

Status : Received

Published: 2025-02-28T03:15:10.363

Modified: 2025-02-28T03:15:10.363

Link: CVE-2024-56340

cve-icon Redhat

No data.