CVE Vulnerabilities

CVE-2024-25036

Authentication Bypass Using an Alternate Path or Channel

Published: Dec 03, 2024 | Modified: Dec 11, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

IBM Cognos Controller 11.0.0 and 11.0.1

could allow an authenticated user with local access to bypass security allowing users to circumvent restrictions imposed on input fields.

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Cognos_controller Ibm 11.0.0 (including) 11.0.0 (including)
Cognos_controller Ibm 11.0.1 (including) 11.0.1 (including)

Potential Mitigations

References