Information Disclosure Vulnerability in IBM Cognos Analytics
CVE-2024-56344
5.9MEDIUM
What is CVE-2024-56344?
IBM Cognos Analytics versions 12.0.4 through 12.0.4 FP2 and 12.1.0 through 12.1.3 FP1 have a vulnerability that could allow remote attackers to access sensitive information. This issue arises from the inadequate implementation of HTTP Strict Transport Security (HSTS), making it possible for attackers to exploit the vulnerability using man-in-the-middle techniques. Therefore, it is crucial for users to apply available patches to mitigate the risk of data exposure.
Affected Version(s)
Cognos Analytics 12.0.4 <= 12.0.4 FP2
Cognos Analytics 12.1.0 <= 12.1.3 FP1