CVE-2024-52902

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 19, 2025
CWE ID 798

Summary

CVE-2024-52902 is a newly disclosed vulnerability affecting IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application. This issue arises due to the presence of hard-coded database passwords in the source code. An attacker who gains unauthorized access to the system could exploit this vulnerability to bypass authentication and gain control over sensitive data or make unauthorized modifications. Organizations using the affected versions are advised to apply the necessary patches or updates to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share