IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7179163 |
History
Tue, 07 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 07 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation. | |
Title | IBM Cognos Controller improper certificate validation | |
First Time appeared |
Ibm
Ibm cognos Controller Ibm controller |
|
Weaknesses | CWE-295 | |
CPEs | cpe:2.3:a:ibm:cognos_controller:11.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_controller:11.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm cognos Controller Ibm controller |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2025-01-07T16:02:36.236Z
Updated: 2025-01-07T16:59:26.656Z
Reserved: 2024-07-08T19:31:12.238Z
Link: CVE-2024-40702
Vulnrichment
Updated: 2025-01-07T16:59:22.092Z
NVD
Status : Received
Published: 2025-01-07T16:15:33.463
Modified: 2025-01-07T16:15:33.463
Link: CVE-2024-40702
Redhat
No data.