CVE-2024-40702
CVSS 3.1 Score 8.2 of 10 (high)
Details
Summary
CVE-2024-40702 is a vulnerability affecting IBM Cognos Controller versions 11.0.0 through 11.0.1 and IBM Controller version 11.1.0. This issue permits unauthorized users to acquire valid tokens, granting them access to protected resources. The root cause lies in the inadequate certificate validation process. These applications fail to verify certificates thoroughly, creating an avenue for attackers to exploit this weakness and potentially gain unauthorized access. IBM strongly advises users to upgrade to the latest versions or apply relevant patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- IBM Cognos Controller
- Controller
Affected Vendors
- IBM Corporation