VDB

CVE-2024-52902

CVE-2024-52902 PUBLISHED CVSS 8.800000190734863 HIGH

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.

EPSS 0.11% · 28.9th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.11%
28.9th percentile

Affected Products

VendorProductVersions
IBMCognos Controller11.0.0
IBMController11.1.0
ibmcognos_controller11.0.0
ibmcontroller11.1.0

Timeline

  • Feb 19, 2025 CVE Published
  • Feb 19, 2025 PoC Published
  • Feb 19, 2025 PoC Published
  • Feb 19, 2025 PoC Published
  • Feb 20, 2025 EPSS Score
  • Mar 6, 2025 EPSS Score
  • Mar 7, 2025 Coalition ESS Score
  • Mar 21, 2025 EPSS Score
  • Apr 4, 2025 EPSS Score
  • Apr 18, 2025 EPSS Score
  • May 2, 2025 EPSS Score
  • May 17, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›