5.5
CVE-2024-40703
- EPSS 0.14%
- Veröffentlicht 22.09.2024 13:15:10
- Zuletzt bearbeitet 27.09.2024 16:49:46
- Erkennungen
IBM Cognos Analytics information disclosure
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cognos Analytics Version >= 11.2.0 <= 11.2.3
Ibm ≫ Cognos Analytics Version >= 12.0.0 < 12.0.3
Ibm ≫ Cognos Analytics Version 11.2.4 Update -
Ibm ≫ Cognos Analytics Version 12.0.3 Update -
Ibm ≫ Cognos Analytics Version 12.0.3 Update interim_fix_1
Ibm ≫ Cognos Analytics Reports Version 11.0.0.7 SwPlatform iphone_os
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.038 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
https://www.ibm.com/support/pages/node/7160700
https://www.ibm.com/support/pages/node/7168038