CVE-2024-41775: IBM Cognos Controller information disclosure
IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Other sources
IBM Controller uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41775?
The severity of CVE-2024-41775 is classified as critical due to the potential for sensitive information decryption.
How do I fix CVE-2024-41775?
To fix CVE-2024-41775, upgrade to a newer version of IBM Cognos Controller that uses stronger cryptographic algorithms.
Which versions of IBM Cognos Controller are affected by CVE-2024-41775?
CVE-2024-41775 affects IBM Cognos Controller versions 11.0.0 and 11.0.1.
What types of information could be compromised by CVE-2024-41775?
CVE-2024-41775 could allow attackers to decrypt highly sensitive information stored in IBM Cognos Controller.
Are there any immediate actions to take regarding CVE-2024-41775?
Immediate actions include evaluating your deployment of IBM Cognos Controller and preparing for an upgrade to mitigate the vulnerability.