CVE-2024-25036

IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user with local access to bypass security allowing users to circumvent restrictions imposed on input fields.
References
Link Resource
https://www.ibm.com/support/pages/node/7177220 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:cognos_controller:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_controller:11.0.1:*:*:*:*:*:*:*

History

11 Dec 2024, 03:35

Type Values Removed Values Added
Summary
  • (es) IBM Cognos Controller 11.0.0 y 11.0.1 podrían permitir que un usuario autenticado con acceso local omita la seguridad, lo que les permitiría eludir las restricciones impuestas en los campos de entrada.
CPE cpe:2.3:a:ibm:cognos_controller:11.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_controller:11.0.0:*:*:*:*:*:*:*
First Time Ibm
Ibm cognos Controller
References () https://www.ibm.com/support/pages/node/7177220 - () https://www.ibm.com/support/pages/node/7177220 - Vendor Advisory

03 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-03 17:15

Updated : 2024-12-11 03:35


NVD link : CVE-2024-25036

Mitre link : CVE-2024-25036

CVE.ORG link : CVE-2024-25036


JSON object : View

Products Affected

ibm

  • cognos_controller
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel