CVE-2024-28777

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 19, 2025
CWE ID 502

Summary

CVE-2024-28777 is a serious vulnerability affecting IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 and IBM Controller version 11.1.0. This issue permits unrestricted deserialization, enabling attackers to execute arbitrary code, escalate privileges, or cause denial of service attacks. By exploiting this vulnerability, malicious actors can gain unauthorized access or cause significant disruption to affected systems. Users are strongly advised to update their IBM Cognos Controller and IBM Controller software to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share