CVE-2024-40702

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 295

Summary

CVE-2024-40702 is a vulnerability affecting IBM Cognos Controller versions 11.0.0 through 11.0.1 and IBM Controller version 11.1.0. This issue permits unauthorized users to acquire valid tokens, granting them access to protected resources. The root cause lies in the inadequate certificate validation process. These applications fail to verify certificates thoroughly, creating an avenue for attackers to exploit this weakness and potentially gain unauthorized access. IBM strongly advises users to upgrade to the latest versions or apply relevant patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • IBM Cognos Controller
  • Controller

Affected Vendors

  • IBM Corporation