CVE-2024-45676: IBM Cognos Controller file upload
IBM Cognos Controller 11.0.0 and 11.0.1
could allow an authenticated user to upload insecure files, due to insufficient file type distinction.
Other sources
IBM Controller could allow an authenticated user to upload insecure files, due to insufficient file type distinction.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45676?
CVE-2024-45676 is classified as a high severity vulnerability due to its potential for unauthorized file uploads.
How do I fix CVE-2024-45676?
To fix CVE-2024-45676, upgrade IBM Cognos Controller to the latest version that addresses this vulnerability.
What is the impact of CVE-2024-45676 on IBM Cognos Controller?
The impact of CVE-2024-45676 allows authenticated users to upload insecure files, posing a risk of data compromise.
Which versions of IBM Cognos Controller are affected by CVE-2024-45676?
CVE-2024-45676 affects IBM Cognos Controller versions 11.0.0 and 11.0.1.
Who can exploit CVE-2024-45676?
CVE-2024-45676 can be exploited by authenticated users of IBM Cognos Controller.