First published: Mon Jan 06 2025(Updated: )
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Controller | <=11.1.0 | |
IBM Cognos Controller | <=11.0.0 - 11.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40702 is considered a critical vulnerability due to the potential for unauthorized access to protected resources.
To fix CVE-2024-40702, upgrade IBM Cognos Controller to version 11.0.2 or later, or IBM Controller to version 11.1.1 or later.
CVE-2024-40702 affects users of IBM Cognos Controller versions 11.0.0 through 11.0.1 and IBM Controller version 11.1.0.
CVE-2024-40702 is a vulnerability related to improper certificate validation, allowing unauthorized users to obtain valid tokens.
The potential impacts of CVE-2024-40702 include unauthorized access to sensitive resources and data breaches.