CVE Published: 02/05/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: ibm |
Vendor: IBM |
Product: Cognos Analytics Status : PUBLISHED
CVE-2024-25047 Description
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.
Metrics
CVSS Version: 3.1 |
Base Score: 8.6 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N