VDB

CVE-2024-25047

CVE-2024-25047 PUBLISHED CVSS 8.600000381469727 HIGH

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.

EPSS 0.64% · 48.9th percentile

Risk Scores

CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
EPSS Score
0.64%
48.9th percentile

Affected Products

VendorProductVersions
ibmcognos_analytics11.2.0, 12.0.0, 11.2.4
netapponcommand_insight
ibmcognos_analytics11.2.0 <= 11.2.4, 12.0.0 <= 12.0.2
IBMCognos Analytics11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2

Timeline

  • May 2, 2024 CVE Published
  • May 3, 2024 EPSS Score
  • May 28, 2024 EPSS Score
  • Jun 23, 2024 EPSS Score
  • Jul 18, 2024 EPSS Score
  • Aug 12, 2024 EPSS Score
  • Sep 5, 2024 EPSS Score
  • Sep 30, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 25, 2024 EPSS Score
  • Nov 19, 2024 EPSS Score
  • Dec 15, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›