PT-2025-7406 · Ibm · Ibm Controller+1

Published

2025-02-18

·

Updated

2025-02-19

·

CVE-2024-28776

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 IBM Controller version 11.1.0
Description This issue allows users to embed arbitrary JavaScript code in the Web UI, altering the intended functionality and potentially leading to credentials disclosure within a trusted session. The vulnerability enables the incorporation of arbitrary JavaScript code, thus changing the expected behavior of the web interface.
Recommendations For IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3, consider disabling the web interface functionality until a patch is available to prevent potential cross-site scripting attacks. For IBM Controller version 11.1.0, restrict access to the web interface to minimize the risk of exploitation. As a temporary workaround, avoid using the web interface for sensitive operations until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02080
CVE-2024-28776

Affected Products

Ibm Cognos Controller
Ibm Controller