PT-2024-28991 · Ibm · Ibm Cognos Analytics Reports For Ios+1

Published

2024-09-22

·

Updated

2024-09-27

·

CVE-2024-40703

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Cognos Analytics versions 11.2.0 through 11.2.4 IBM Cognos Analytics versions 12.0.0 through 12.0.3 IBM Cognos Analytics Reports for iOS version 11.0.0.7
Description A local attacker could obtain sensitive information in the form of an API key. This information could be used to launch further attacks against affected applications.
Recommendations For IBM Cognos Analytics versions 11.2.0 through 11.2.4, consider restricting access to sensitive information until a patch is available. For IBM Cognos Analytics versions 12.0.0 through 12.0.3, consider restricting access to sensitive information until a patch is available. For IBM Cognos Analytics Reports for iOS version 11.0.0.7, consider restricting access to sensitive information until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-40703

Affected Products

Ibm Cognos Analytics
Ibm Cognos Analytics Reports For Ios