VDB
CVE-2024-52902
CVE-2024-52902
PUBLISHED
CVSS 8.800000190734863 HIGH
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.
EPSS 0.11% · 28.9th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.11%
28.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| IBM | Cognos Controller | 11.0.0 |
| IBM | Controller | 11.1.0 |
| ibm | cognos_controller | 11.0.0 |
| ibm | controller | 11.1.0 |
Exploit Intelligence
- CIRCL seen: CVE-2024-52902 (circl-sighting)
- CIRCL seen: CVE-2024-52902 (circl-sighting)
- CIRCL seen: CVE-2024-52902 (circl-sighting)
- CIRCL seen: CVE-2024-52902 (circl-sighting)
- https://www.ibm.com/support/pages/node/7183597 (circl)
Timeline
- Feb 19, 2025 CVE Published
- Feb 19, 2025 PoC Published
- Feb 19, 2025 PoC Published
- Feb 19, 2025 PoC Published
- Feb 20, 2025 EPSS Score
- Mar 6, 2025 EPSS Score
- Mar 7, 2025 Coalition ESS Score
- Mar 21, 2025 EPSS Score
- Apr 4, 2025 EPSS Score
- Apr 18, 2025 EPSS Score
- May 2, 2025 EPSS Score
- May 17, 2025 EPSS Score