CVE-2024-25035: IBM Cognos Controller information disclosure
IBM Cognos Controller 11.0.0 and 11.0.1
exposes server details that could allow an attacker to obtain information of the application environment to conduct further attacks.
Other sources
IBM Cognos Controller exposes server details that could allow an attacker to obtain information of the application environment to conduct further attacks.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25035?
CVE-2024-25035 has been rated with a medium severity, indicating potential risks associated with server detail exposure.
How do I fix CVE-2024-25035?
To remediate CVE-2024-25035, upgrade to IBM Cognos Controller version 11.0.2 or later where the issue is addressed.
What vulnerabilities are associated with CVE-2024-25035?
CVE-2024-25035 exposes server details that could allow attackers to gather information for further attacks.
Which versions of IBM Cognos Controller are affected by CVE-2024-25035?
IBM Cognos Controller versions 11.0.0 and 11.0.1 are affected by CVE-2024-25035.
What type of attack can CVE-2024-25035 facilitate?
CVE-2024-25035 can facilitate information gathering attacks, enabling attackers to exploit server details.