Expression Language Injection Vulnerability in IBM Cognos Analytics
CVE-2024-51466

9CRITICAL

Key Information:

Vendor
IBM
Vendor
CVE Published:
20 December 2024

Badges

đź“° News Worthy

Summary

CVE-2024-51466 identifies a critical Expression Language (EL) Injection vulnerability found in IBM Cognos Analytics versions 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4. This vulnerability allows remote attackers to manipulate EL statements, potentially exposing sensitive information, monopolizing system memory resources, and leading to server crashes. Organizations using affected versions should prioritize updating their systems to mitigate these risks and protect against potential exploitation.

News Articles

IBM Cognos Analytics Vulnerability Allows Malicious File Upload & Injection Attacks

IBM has released a critical security update for its Cognos Analytics software, addressing two severe vulnerabilities: CVE-2023-42017 and CVE-2024-51466.

1 month ago

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • đź“°

    First article discovered by CybersecurityNews

  • Vulnerability published

.