CVE-2024-28777
HIGHIBM Cognos Controller < 11.0.1.4 - Insecure Deserialization
Title source: ruleDescription
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate privileges, or cause denial of service attacks by exploiting the unrestricted deserialization of types in the application.
Scores
CVSS v3
8.8
EPSS
0.0120
EPSS Percentile
78.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (2)
ibm/cognos_controller
< 11.0.1.4
ibm/controller
Timeline
Published
Feb 19, 2025
Tracked Since
Feb 18, 2026