PT-2024-10079 · Ibm · Ibm Controller+1

Published

2024-07-08

·

Updated

2025-01-07

·

CVE-2024-40702

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Cognos Controller versions 11.0.0 through 11.0.1 IBM Controller version 11.1.0
Description The issue is related to improper certificate validation, which could allow a remote attacker to gain unauthorized access to protected information. This may enable an unauthorized user to obtain valid tokens and access protected resources.
Recommendations For IBM Cognos Controller versions 11.0.0 through 11.0.1, update to a version that properly validates certificates to prevent unauthorized access. For IBM Controller version 11.1.0, update to a version that properly validates certificates to prevent unauthorized access. As a temporary workaround, consider restricting access to protected resources until a patch is available.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2025-00250
CVE-2024-40702

Affected Products

Ibm Cognos Controller
Ibm Controller