Expression Language Injection Vulnerability in IBM Cognos Analytics
CVE-2024-51466
9CRITICAL
Summary
CVE-2024-51466 identifies a critical Expression Language (EL) Injection vulnerability found in IBM Cognos Analytics versions 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4. This vulnerability allows remote attackers to manipulate EL statements, potentially exposing sensitive information, monopolizing system memory resources, and leading to server crashes. Organizations using affected versions should prioritize updating their systems to mitigate these risks and protect against potential exploitation.
Get notified when SecurityVulnerability.io launches alerting đź””
Well keep you posted 📧
News Articles
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
- đź“°
First article discovered by CybersecurityNews
Vulnerability published