CVE-2024-28780: IBM Cognos Controller information disclosure
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client
uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28780?
The severity of CVE-2024-28780 is classified as high due to the potential for attackers to decrypt sensitive information.
How do I fix CVE-2024-28780?
To fix CVE-2024-28780, upgrade to the latest version of IBM Cognos Controller and IBM Controller that address the cryptographic weaknesses.
What versions are affected by CVE-2024-28780?
CVE-2024-28780 affects IBM Cognos Controller versions 11.0.0 to 11.0.1 FP3 and IBM Controller version 11.1.0.
What type of vulnerability is CVE-2024-28780?
CVE-2024-28780 is a cryptographic vulnerability that allows for the decryption of highly sensitive information.
Can CVE-2024-28780 be exploited remotely?
Yes, CVE-2024-28780 may be exploited remotely by attackers who can access the affected systems.