First published: Tue Dec 03 2024(Updated: )
IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Controller | <=11.0.0 - 11.0.1 | |
IBM Cognos Controller | =11.0.0 | |
IBM Cognos Controller | =11.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41777 has a medium severity rating due to the presence of hard-coded credentials in IBM Cognos Controller versions 11.0.0 and 11.0.1.
To mitigate CVE-2024-41777, upgrade IBM Cognos Controller to the latest version where the hard-coded credentials issue has been resolved.
CVE-2024-41777 affects IBM Cognos Controller versions 11.0.0 and 11.0.1.
The risks associated with CVE-2024-41777 include unauthorized access and potential data exposure due to the use of hard-coded credentials.
There are currently no reports indicating that CVE-2024-41777 is being actively exploited in the wild.