CVE Vulnerabilities

CVE-2024-40703

Insufficiently Protected Credentials

Published: Sep 22, 2024 | Modified: Sep 27, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Cognos_analyticsIbm11.2.0 (including)11.2.3 (including)
Cognos_analyticsIbm12.0.0 (including)12.0.3 (excluding)
Cognos_analyticsIbm11.2.4 (including)11.2.4 (including)
Cognos_analyticsIbm12.0.3 (including)12.0.3 (including)
Cognos_analyticsIbm12.0.3-interim_fix_1 (including)12.0.3-interim_fix_1 (including)
Cognos_analytics_reportsIbm11.0.0.7 (including)11.0.0.7 (including)

Potential Mitigations

References