CVE Vulnerabilities

CVE-2024-25036

Authentication Bypass Using an Alternate Path or Channel

Published: Dec 03, 2024 | Modified: Dec 11, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Cognos Controller 11.0.0 and 11.0.1

could allow an authenticated user with local access to bypass security allowing users to circumvent restrictions imposed on input fields.

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Cognos_controller Ibm 11.0.0 (including) 11.0.0 (including)
Cognos_controller Ibm 11.0.1 (including) 11.0.1 (including)

Potential Mitigations

References