6.5
CVE-2024-56340
- EPSS 0.81%
- Veröffentlicht 28.02.2025 03:15:10
- Zuletzt bearbeitet 17.10.2025 16:15:36
- Erkennungen
IBM Cognos Analytics path traversal
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cognos Analytics Version >= 11.2.0 < 11.2.4
Ibm ≫ Cognos Analytics Version >= 12.0.0 < 12.0.4
Ibm ≫ Cognos Analytics Version 11.2.4 Update -
Ibm ≫ Cognos Analytics Version 11.2.4 Update fixpack1
Ibm ≫ Cognos Analytics Version 11.2.4 Update fixpack2
Ibm ≫ Cognos Analytics Version 11.2.4 Update fixpack3
Ibm ≫ Cognos Analytics Version 11.2.4 Update fixpack4
Ibm ≫ Cognos Analytics Version 11.2.4 Update fixpack5
Ibm ≫ Cognos Analytics Version 12.0.4 Update -
Ibm ≫ Cognos Analytics Version 12.0.4 Update interim_fix_1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.81% | 0.531 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-23 Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
https://www.ibm.com/support/pages/node/7183676
https://github.com/MarioTesoro/vulnerability-research/tree/main/CVE-2024-56340