CVE-2024-28776
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Feb 19, 2025
CWE ID 79
Summary
CVE-2024-28776 is a cross-site scripting (XSS) vulnerability affecting IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 and IBM Controller version 11.1.0. This issue permits users to inject malicious JavaScript code into the Web UI, altering the intended functionality and potentially leading to sensitive data disclosure, such as credentials, within a secure user session. IBM has released patches to address this vulnerability, and it is recommended that affected organizations apply these updates promptly to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share