First published: Wed Nov 06 2024(Updated: )
Apache ZooKeeper could allow a remote attacker to bypass security restrictions, caused by a flaw when using IPAuthenticationProvider. By spoofing client's IP address in request headers, an attacker could exploit this vulnerability to bypass authentication.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51504 is classified as a high-severity vulnerability due to its ability to allow remote attackers to bypass authentication.
To fix CVE-2024-51504, apply the necessary patches provided by IBM for affected versions of Cognos Analytics.
CVE-2024-51504 affects IBM Cognos Analytics version 11.2.0 to 11.2.4 FP4 and 12.0.0 to 12.0.3.
An attacker can exploit CVE-2024-51504 to bypass security restrictions by spoofing the client's IP address.
Yes, CVE-2024-51504 is exploitable remotely, allowing attackers to manipulate request headers from external sources.