CVE Vulnerabilities

CVE-2024-55907

Inclusion of Sensitive Information in Source Code

Published: Mar 02, 2025 | Modified: Jul 30, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used due to weak obfuscation.

Weakness

Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.

Affected Software

Name Vendor Start Version End Version
Cognos_analytics_mobile Ibm 1.1.0 (including) 1.1.21 (excluding)

Potential Mitigations

References