← Back

CVE-2024-40703

nvd nist
Published: Sep 22, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: psirt@us.ibm.com (Secondary)

Description

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.

Affected (6)

2 products
Cognos Analytics
Cognos Analytics Reports
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 11.2.0 to 11.2.3
From 12.0.0 to 12.0.3
Version 11.2.4
Version 12.0.3
Version 12.0.3 interim_fix_1
Version 11.0.0.7

References (2)

Source: psirt@us.ibm.com
PatchVendor Advisory
Source: psirt@us.ibm.com
PatchVendor Advisory

Timeline

No history available yet.