IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user with local access to bypass security allowing users to circumvent restrictions imposed on input fields.
History

Tue, 03 Dec 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Dec 2024 17:00:00 +0000

Type Values Removed Values Added
Description IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user with local access to bypass security allowing users to circumvent restrictions imposed on input fields.
Title IBM Cognos Controller authentication bypass
First Time appeared Ibm
Ibm cognos Controller
Weaknesses CWE-288
CPEs cpe:2.3:a:ibm:cognos_controller:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_controller:11.0.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Controller
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2024-12-03T16:44:55.741Z

Updated: 2024-12-03T19:09:42.192Z

Reserved: 2024-02-03T14:49:24.713Z

Link: CVE-2024-25036

cve-icon Vulnrichment

Updated: 2024-12-03T19:09:36.455Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-03T17:15:09.923

Modified: 2024-12-11T03:35:51.663

Link: CVE-2024-25036

cve-icon Redhat

No data.