CVE-2024-45084: IBM Cognos Controller CSV injection
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45084?
CVE-2024-45084 is rated as a critical vulnerability due to its potential for arbitrary command execution by an authenticated attacker.
How do I fix CVE-2024-45084?
To fix CVE-2024-45084, update IBM Cognos Controller to version 11.0.1 FP4 or later, and ensure all security patches are applied.
Which versions of IBM software are affected by CVE-2024-45084?
CVE-2024-45084 affects IBM Cognos Controller versions 11.0.0 through 11.0.1 FP3 and IBM Controller version 11.1.0.
Can an unauthenticated user exploit CVE-2024-45084?
No, CVE-2024-45084 requires authentication to exploit the formula injection flaw.
What type of attack can be conducted using CVE-2024-45084?
CVE-2024-45084 can be used by an attacker to perform formula injection, potentially executing arbitrary commands on the system.