5.5

CVE-2024-40703

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key.  An attacker could use this information to launch further attacks against affected applications.

Data is provided by the National Vulnerability Database (NVD)
IbmCognos Analytics Version >= 11.2.0 <= 11.2.3
IbmCognos Analytics Version >= 12.0.0 < 12.0.3
IbmCognos Analytics Version11.2.4 Update-
IbmCognos Analytics Version12.0.3 Update-
IbmCognos Analytics Version12.0.3 Updateinterim_fix_1
IbmCognos Analytics Reports Version11.0.0.7 SwPlatformiphone_os
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.037
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
psirt@us.ibm.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.