Unauthorized Access Risk in IBM Cognos Controller and IBM Controller Products
CVE-2024-40702
8.2HIGH
Summary
IBM Cognos Controller versions 11.0.0 through 11.0.1 and IBM Controller version 11.1.0 are susceptible to a vulnerability that could allow unauthorized users to obtain valid tokens, granting them access to protected resources. This flaw arises from improper validation of certificates, highlighting the need for rigorous security measures to prevent unauthorized resource access.
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published