Information Disclosure Vulnerability in IBM Cognos Controller and IBM Controller
CVE-2024-25037

4.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
7 January 2025

What is CVE-2024-25037?

IBM Cognos Controller versions 11.0.0 to 11.0.1 and IBM Controller version 11.1.0 are vulnerable to an information disclosure issue. This vulnerability allows remote attackers to gain access to sensitive information through stack traces that may be inadvertently returned in the browser, potentially leading to exposure of confidential data.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-25037 : Information Disclosure Vulnerability in IBM Cognos Controller and IBM Controller