First published: Fri Dec 20 2024(Updated: )
IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.4 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40695 has been classified with a critical severity due to the potential for attackers to upload malicious files.
To fix CVE-2024-40695, users should apply the latest patches provided by IBM for affected versions of Cognos Analytics.
CVE-2024-40695 affects IBM Cognos Analytics versions from 11.2.0 to 11.2.4 FP4 and from 12.0.0 to 12.0.4.
The vulnerability allows attackers to upload malicious executable files due to improper file content validation.
Mitigating the risk of CVE-2024-40695 without a patch can be challenging, but restricting file upload capabilities may reduce exposure.