First published: Tue Dec 17 2024(Updated: )
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
IBM Cognos Analytics | >=11.2.0<=11.2.4 | |
IBM Cognos Analytics | >=12.0.0<=12.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45082 is classified as a medium severity vulnerability that allows remote attackers to execute phishing attacks.
You can fix CVE-2024-45082 by applying the latest patches provided by IBM for affected versions of Cognos Analytics.
Versions 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 of IBM Cognos Analytics are affected by CVE-2024-45082.
Yes, CVE-2024-45082 can be exploited by persuading a victim to visit a specially crafted website, enabling phishing attacks.
CVE-2024-45082 facilitates phishing attacks through an open redirect vulnerability.