4.3
CVE-2024-45676
- EPSS 0.04%
- Published 03.12.2024 18:15:14
- Last modified 11.12.2024 03:21:10
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insufficient file type distinction.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Cognos Controller Version11.0.0
Ibm ≫ Cognos Controller Version11.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.124 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@us.ibm.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-351 Insufficient Type Distinction
The product does not properly distinguish between different types of elements in a way that leads to insecure behavior.