CVE-2024-51466
CVSS 3.1 Score 9 of 10 (high)
Details
Published Dec 20, 2024
CWE ID 917
Summary
CVE-2024-51466 is a newly disclosed vulnerability affecting IBM Cognos Analytics versions 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4. This issue involves an Expression Language (EL) Injection vulnerability, which allows a remote attacker to manipulate EL statements in a way that exposes sensitive information, consumes excessive memory resources, and crashes the server. Successful exploitation could lead to significant data breaches or system instability. IBM strongly advises users to apply the appropriate patches or upgrades to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.