First published: Fri Dec 20 2024(Updated: )
IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, and/or cause the server to crash when using a specially crafted EL statement.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.4 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51466 is classified with a medium severity level due to its potential for information exposure and resource consumption.
To fix CVE-2024-51466, apply the relevant patches provided by IBM for Cognos Analytics versions 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4.
Users of IBM Cognos Analytics versions 11.2.0 to 11.2.4 FP4 and 12.0.0 to 12.0.4 are affected by CVE-2024-51466.
CVE-2024-51466 is an Expression Language (EL) Injection vulnerability that can be exploited by remote attackers.
By exploiting CVE-2024-51466, an attacker could expose sensitive information, consume memory resources, and potentially disrupt server operations.