Information Disclosure Vulnerability in IBM Cognos Analytics
CVE-2024-56344

5.9MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2024-56344?

IBM Cognos Analytics versions 12.0.4 through 12.0.4 FP2 and 12.1.0 through 12.1.3 FP1 have a vulnerability that could allow remote attackers to access sensitive information. This issue arises from the inadequate implementation of HTTP Strict Transport Security (HSTS), making it possible for attackers to exploit the vulnerability using man-in-the-middle techniques. Therefore, it is crucial for users to apply available patches to mitigate the risk of data exposure.

Affected Version(s)

Cognos Analytics 12.0.4 <= 12.0.4 FP2

Cognos Analytics 12.1.0 <= 12.1.3 FP1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.