First published: Thu Jan 09 2025(Updated: )
The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Controller | <=11.1.0 | |
IBM Cognos Controller | <=11.0.0 - 11.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37372 is considered a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2024-37372, users should update IBM Planning Analytics to version 2.1 or later.
CVE-2024-37372 affects IBM Planning Analytics versions up to and including 2.1 and 2.0.
CVE-2024-37372 can be exploited by attackers through improper processing of UNC paths leading to potential security bypass.
CVE-2024-37372 is caused by the Permission Model's improper handling of paths that start with two backslashes.