IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/7183676 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
02 Jul 2025, 15:59
Type | Values Removed | Values Added |
---|---|---|
First Time |
Ibm
Ibm cognos Analytics |
|
CPE | cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:12.0.4:interim_fix_1:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack4:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:12.0.4:-:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack5:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack3:*:*:*:*:*:* |
|
Summary |
|
|
References | () https://www.ibm.com/support/pages/node/7183676 - Patch, Vendor Advisory |
28 Feb 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-28 03:15
Updated : 2025-07-02 15:59
NVD link : CVE-2024-56340
Mitre link : CVE-2024-56340
CVE.ORG link : CVE-2024-56340
JSON object : View
Products Affected
ibm
- cognos_analytics
CWE
CWE-23
Relative Path Traversal