5.5
CVE-2024-40703
- EPSS 0.02%
- Published 22.09.2024 13:15:10
- Last modified 27.09.2024 16:49:46
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Cognos Analytics Version >= 11.2.0 <= 11.2.3
Ibm ≫ Cognos Analytics Version >= 12.0.0 < 12.0.3
Ibm ≫ Cognos Analytics Version11.2.4 Update-
Ibm ≫ Cognos Analytics Version12.0.3 Update-
Ibm ≫ Cognos Analytics Version12.0.3 Updateinterim_fix_1
Ibm ≫ Cognos Analytics Reports Version11.0.0.7 SwPlatformiphone_os
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.037 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@us.ibm.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.