CVE-2024-49352: IBM Cognos Anaytics XML external entity injection
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49352?
CVE-2024-49352 is classified as a medium severity vulnerability due to the potential for data exposure and resource consumption.
How do I fix CVE-2024-49352?
To fix CVE-2024-49352, users should apply the appropriate patches provided by IBM for their version of IBM Cognos Analytics.
Who is affected by CVE-2024-49352?
CVE-2024-49352 affects users of IBM Cognos Analytics versions 11.2.0 through 11.2.4 and 12.0.0 through 12.0.4.
What kind of attack is CVE-2024-49352 related to?
CVE-2024-49352 is related to an XML External Entity Injection (XXE) attack that can expose sensitive information.
Can CVE-2024-49352 be exploited remotely?
Yes, CVE-2024-49352 can be exploited remotely, allowing attackers to manipulate XML data to gain unauthorized access.