CVE Vulnerabilities

CVE-2024-40702

Improper Certificate Validation

Published: Jan 07, 2025 | Modified: Jul 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Cognos_controller Ibm 11.0.0 (including) 11.0.1 (including)
Controller Ibm 11.1.0 (including) 11.1.0 (including)

Potential Mitigations

References