6.5
CVE-2024-56340
- EPSS 12.22%
- Veröffentlicht 28.02.2025 03:15:10
- Zuletzt bearbeitet 17.10.2025 16:15:36
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Cognos Analytics path traversal
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cognos Analytics Version >= 11.2.0 < 11.2.4
Ibm ≫ Cognos Analytics Version >= 12.0.0 < 12.0.4
Ibm ≫ Cognos Analytics Version11.2.4 Update-
Ibm ≫ Cognos Analytics Version11.2.4 Updatefixpack1
Ibm ≫ Cognos Analytics Version11.2.4 Updatefixpack2
Ibm ≫ Cognos Analytics Version11.2.4 Updatefixpack3
Ibm ≫ Cognos Analytics Version11.2.4 Updatefixpack4
Ibm ≫ Cognos Analytics Version11.2.4 Updatefixpack5
Ibm ≫ Cognos Analytics Version12.0.4 Update-
Ibm ≫ Cognos Analytics Version12.0.4 Updateinterim_fix_1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 12.22% | 0.938 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-23 Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.