6.5
CVE-2024-56340
- EPSS 1.45%
- Veröffentlicht 28.02.2025 03:15:10
- Zuletzt bearbeitet 17.10.2025 16:15:36
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cognos Analytics Version >= 11.2.0 < 11.2.4
Ibm ≫ Cognos Analytics Version >= 12.0.0 < 12.0.4
Ibm ≫ Cognos Analytics Version11.2.4 Update-
Ibm ≫ Cognos Analytics Version11.2.4 Updatefixpack1
Ibm ≫ Cognos Analytics Version11.2.4 Updatefixpack2
Ibm ≫ Cognos Analytics Version11.2.4 Updatefixpack3
Ibm ≫ Cognos Analytics Version11.2.4 Updatefixpack4
Ibm ≫ Cognos Analytics Version11.2.4 Updatefixpack5
Ibm ≫ Cognos Analytics Version12.0.4 Update-
Ibm ≫ Cognos Analytics Version12.0.4 Updateinterim_fix_1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.45% | 0.802 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-23 Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.