IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.ibm.com/support/pages/node/7183597 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    25 Jul 2025, 19:12
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://www.ibm.com/support/pages/node/7183597 - Vendor Advisory | |
| CPE | cpe:2.3:a:ibm:cognos_controller:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:* | |
| First Time | Microsoft Ibm Microsoft windows Ibm controller Ibm cognos Controller | |
| Summary | 
 | 
19 Feb 2025, 15:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-02-19 15:15
Updated : 2025-07-25 19:12
NVD link : CVE-2024-52902
Mitre link : CVE-2024-52902
CVE.ORG link : CVE-2024-52902
JSON object : View
Products Affected
                ibm
- cognos_controller
- controller
microsoft
- windows
CWE
                
                    
                        
                        CWE-798
                        
            Use of Hard-coded Credentials
