VDB
CVE-2024-25047
CVE-2024-25047
PUBLISHED
CVSS 8.600000381469727 HIGH
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.
EPSS 0.06% · 18.1th percentile
Risk Scores
CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
EPSS Score
0.06%
18.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ibm | cognos_analytics | 11.2.0, 12.0.0, 11.2.4 |
| netapp | oncommand_insight | |
| ibm | cognos_analytics | 11.2.0 <= 11.2.4, 12.0.0 <= 12.0.2 |
| IBM | Cognos Analytics | 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2 |
Timeline
- May 2, 2024 CVE Published
- May 3, 2024 EPSS Score
- May 27, 2024 EPSS Score
- Jun 22, 2024 EPSS Score
- Jul 16, 2024 EPSS Score
- Aug 9, 2024 EPSS Score
- Sep 3, 2024 EPSS Score
- Sep 27, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 21, 2024 EPSS Score
- Nov 14, 2024 EPSS Score
- Dec 10, 2024 EPSS Score
References
- https://www.ibm.com/support/pages/node/7149736 advisory
- https://www.ibm.com/support/pages/node/7150045 advisory
- https://www.ibm.com/support/pages/node/7149967 advisory
- https://www.ibm.com/support/pages/node/7149874 advisory
- https://www.ibm.com/support/pages/node/7150150 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/282956 vdb
- https://security.netapp.com/advisory/ntap-20240621-0007/ url
- https://nvd.nist.gov/vuln/detail/CVE-2024-25047 advisory
- https://security.netapp.com/advisory/ntap-20240621-0007 url