First published: Tue Dec 17 2024(Updated: )
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
IBM Cognos Analytics | >=11.2.0<=11.2.4 | |
IBM Cognos Analytics | >=12.0.0<=12.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41752 is classified as a high severity vulnerability due to its potential for HTML injection that could enable remote attacks.
To fix CVE-2024-41752, you should apply the latest patches provided by IBM for the affected versions of Cognos Analytics.
CVE-2024-41752 affects IBM Cognos Analytics versions 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3.
CVE-2024-41752 allows remote attackers to perform HTML injection, potentially executing malicious code in victims' browsers.
No, CVE-2024-41752 can be exploited remotely without authentication, making it particularly dangerous.