CVE Vulnerabilities

CVE-2024-31899

Plaintext Storage of a Password

Published: Sep 26, 2024 | Modified: Jan 07, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Affected Software

NameVendorStart VersionEnd Version
Cognos_command_centerIbm10.2.4.1 (including)10.2.4.1 (including)
Cognos_command_centerIbm10.2.5 (including)10.2.5 (including)

Potential Mitigations

References