PT-2024-10079 · Ibm · Ibm Controller+1
Published
2024-07-08
·
Updated
2025-01-07
·
CVE-2024-40702
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Cognos Controller versions 11.0.0 through 11.0.1
IBM Controller version 11.1.0
Description
The issue is related to improper certificate validation, which could allow a remote attacker to gain unauthorized access to protected information. This may enable an unauthorized user to obtain valid tokens and access protected resources.
Recommendations
For IBM Cognos Controller versions 11.0.0 through 11.0.1, update to a version that properly validates certificates to prevent unauthorized access.
For IBM Controller version 11.1.0, update to a version that properly validates certificates to prevent unauthorized access.
As a temporary workaround, consider restricting access to protected resources until a patch is available.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Cognos Controller
Ibm Controller