4.3

CVE-2024-45676

IBM Cognos Controller 11.0.0 and 11.0.1 







could allow an authenticated user to upload insecure files, due to insufficient file type distinction.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmCognos Controller Version11.0.0
IbmCognos Controller Version11.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.124
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-351 Insufficient Type Distinction

The product does not properly distinguish between different types of elements in a way that leads to insecure behavior.