First published: Tue Feb 18 2025(Updated: )
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Controller | >=11.0.0<=11.0.1 FP3 | |
IBM Controller | =11.1.0 | |
IBM Cognos Controller | <=11.0.0 - 11.0.1 FP3 | |
IBM Controller | <=11.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45084 is rated as a critical vulnerability due to its potential for arbitrary command execution by an authenticated attacker.
To fix CVE-2024-45084, update IBM Cognos Controller to version 11.0.1 FP4 or later, and ensure all security patches are applied.
CVE-2024-45084 affects IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 and IBM Controller version 11.1.0.
No, CVE-2024-45084 requires authentication to exploit the formula injection flaw.
CVE-2024-45084 can be used by an attacker to perform formula injection, potentially executing arbitrary commands on the system.