5.9
CVE-2024-56344
- EPSS 0.17%
- Veröffentlicht 18.09.2026 14:29:49
- Zuletzt bearbeitet 28.09.2026 14:10:00
- Erkennungen
IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vulnerabilities
IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerIBM
≫
Produkt
Cognos Analytics
Version <=
12.0.4 FP2
Version
12.0.4
Status
affected
Version <=
12.1.3 FP1
Version
12.1.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.061 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
https://www.ibm.com/support/pages/node/7287211