IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7183597 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
25 Jul 2025, 19:12
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_controller:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:* |
|
| References | () https://www.ibm.com/support/pages/node/7183597 - Vendor Advisory | |
| First Time |
Microsoft windows
Ibm controller Ibm Ibm cognos Controller Microsoft |
19 Feb 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-02-19 15:15
Updated : 2025-07-25 19:12
NVD link : CVE-2024-52902
Mitre link : CVE-2024-52902
CVE.ORG link : CVE-2024-52902
JSON object : View
Products Affected
ibm
- cognos_controller
- controller
microsoft
- windows
CWE
CWE-798
Use of Hard-coded Credentials
