CVE-2024-31899: IBM Cognos Command Center information disclosure
Published Sep 25, 2024
·Updated
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device.
Other sources
IBM Cognos Command Center could disclose highly sensitive user information to an authenticated user with physical access to the device.
— IBM
Affected Software
4 affected components
IBM Cognos Command Center<=10.2.5
IBM Cognos Command Center<=10.2.4.1
IBM Cognos Command Center=10.2.4.1
IBM Cognos Command Center=10.2.5
Event History
Sep 25, 2024
CVE Published
via IBM·12:00 AM
Sep 26, 2024
CVE Published
via MITRE·01:34 PM
Data Sourced
via MITRE·01:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31899?
CVE-2024-31899 has a high severity due to its potential for disclosing highly sensitive user information.
2
How do I fix CVE-2024-31899?
To fix CVE-2024-31899, upgrade IBM Cognos Command Center to the latest versions beyond 10.2.5.
3
Who is affected by CVE-2024-31899?
CVE-2024-31899 affects users of IBM Cognos Command Center versions 10.2.4.1 and 10.2.5.
4
What type of data is vulnerable in CVE-2024-31899?
CVE-2024-31899 can potentially expose highly sensitive user information.
5
Can CVE-2024-31899 be exploited remotely?
CVE-2024-31899 requires physical access to the device for exploitation.