CVE-2024-41776: IBM Cognos Controller cross-site request forgery
IBM Cognos Controller 11.0.0 and 11.0.1
is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Other sources
IBM Controller is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41776?
CVE-2024-41776 is considered a medium severity vulnerability due to its potential for unauthorized actions through cross-site request forgery.
How do I fix CVE-2024-41776?
To fix CVE-2024-41776, it is recommended to apply the latest security patches from IBM for Cognos Controller.
Which versions of IBM Cognos Controller are affected by CVE-2024-41776?
CVE-2024-41776 affects IBM Cognos Controller versions 11.0.0 and 11.0.1.
What types of attacks are possible due to CVE-2024-41776?
CVE-2024-41776 allows attackers to execute malicious and unauthorized actions via cross-site request forgery.
Is there a workaround for CVE-2024-41776?
Currently, no specific workaround has been recommended for CVE-2024-41776, so applying updates is essential.