CVE-2024-40703

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.3:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.3:interim_fix_1:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics_reports:11.0.0.7:*:*:*:*:iphone_os:*:*

History

27 Sep 2024, 16:49

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7160700 - () https://www.ibm.com/support/pages/node/7160700 - Patch, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7168038 - () https://www.ibm.com/support/pages/node/7168038 - Patch, Vendor Advisory
First Time Ibm cognos Analytics Reports
Ibm
Ibm cognos Analytics
CPE cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics_reports:11.0.0.7:*:*:*:*:iphone_os:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.3:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.3:interim_fix_1:*:*:*:*:*:*

26 Sep 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3 e IBM Cognos Analytics Reports para iOS 11.0.0.7 podrían permitir que un atacante local obtenga información confidencial en forma de una clave API. Un atacante podría utilizar esta información para lanzar otros ataques contra las aplicaciones afectadas.

22 Sep 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-22 13:15

Updated : 2024-09-27 16:49


NVD link : CVE-2024-40703

Mitre link : CVE-2024-40703

CVE.ORG link : CVE-2024-40703


JSON object : View

Products Affected

ibm

  • cognos_analytics_reports
  • cognos_analytics
CWE
CWE-522

Insufficiently Protected Credentials