4.3

CVE-2024-25036

IBM Cognos Controller authentication bypass

IBM Cognos Controller 11.0.0 and 11.0.1 





could allow an authenticated user with local access to bypass security allowing users to circumvent restrictions imposed on input fields.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmCognos Controller Version11.0.0
IbmCognos Controller Version11.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.005
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
psirt@us.ibm.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.