CVE-2024-40702

HIGH

IBM Cognos Controller <11.0.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.

References (1)

Core 1
Core References

Scores

CVSS v3 8.2
EPSS 0.0010
EPSS Percentile 26.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (2)
ibm/cognos_controller 11.0.0 - 11.0.1
ibm/controller 11.1.0
Published Jan 07, 2025
Tracked Since Feb 18, 2026