CVE-2024-28778

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 7, 2025
CWE ID 798

Summary

CVE-2024-28778 is a newly disclosed vulnerability affecting IBM Cognos Controller versions 11.0.0 through 11.0.1 and IBM Controller version 11.1.0. This issue grants unauthorized users access to Artifactory API keys, potentially enabling them to publish code to private packages or repositories under the organization's name. The exposure of these keys can lead to serious data breaches or unauthorized system changes. IBM strongly recommends upgrading to the latest version or applying the provided patch to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • IBM Cognos Controller
  • Controller

Affected Vendors

  • IBM Corporation