CVE Vulnerabilities

CVE-2024-40703

Insufficiently Protected Credentials

Published: Sep 22, 2024 | Modified: Sep 27, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Cognos_analytics Ibm 11.2.0 (including) 11.2.3 (including)
Cognos_analytics Ibm 12.0.0 (including) 12.0.3 (excluding)
Cognos_analytics Ibm 11.2.4 (including) 11.2.4 (including)
Cognos_analytics Ibm 12.0.3 (including) 12.0.3 (including)
Cognos_analytics Ibm 12.0.3-interim_fix_1 (including) 12.0.3-interim_fix_1 (including)
Cognos_analytics_reports Ibm 11.0.0.7 (including) 11.0.0.7 (including)

Potential Mitigations

References