CVE-2024-25047: IBM Cognos Analytics log injection
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.
Other sources
IBM Cognos Analytics is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25047?
CVE-2024-25047 is considered a high severity vulnerability due to its potential for injection attacks.
How do I fix CVE-2024-25047?
To fix CVE-2024-25047, update IBM Cognos Analytics to versions 11.2.4 FP3 or 12.0.3 or later.
What versions of IBM Cognos Analytics are affected by CVE-2024-25047?
CVE-2024-25047 affects IBM Cognos Analytics versions 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2.
What type of attacks can CVE-2024-25047 facilitate?
CVE-2024-25047 can facilitate injection attacks due to the lack of sanitization of user-provided data.
Who reported CVE-2024-25047?
CVE-2024-25047 was reported by IBM X-Force, with the ID 282956.