CVE-2024-40703: IBM Cognos Analytics information disclosure
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.
Other sources
IBM Cognos Analytics could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40703?
CVE-2024-40703 has been classified as a moderate severity vulnerability due to the potential exposure of sensitive API keys.
How do I fix CVE-2024-40703?
To mitigate CVE-2024-40703, update IBM Cognos Analytics and IBM Cognos Analytics Reports for iOS to the latest versions recommended by IBM.
What are the affected versions for CVE-2024-40703?
CVE-2024-40703 affects IBM Cognos Analytics versions 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3, as well as Cognos Analytics Reports for iOS version 11.0.0.7.
Can CVE-2024-40703 be exploited remotely?
CVE-2024-40703 is a local vulnerability, meaning an attacker would need local access to exploit it and gain sensitive information.
What information can be compromised due to CVE-2024-40703?
Exploitation of CVE-2024-40703 can lead to the unauthorized disclosure of sensitive information, specifically API keys.