CVE-2024-56340: IBM Cognos Analytics path traversal
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
Other sources
IBM Cognos Analytics is vulnerable to local file inclusion vulnerablity, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56340?
CVE-2024-56340 has a critical severity rating due to its potential to expose sensitive files via local file inclusion.
How do I fix CVE-2024-56340?
To fix CVE-2024-56340, apply the patches provided by IBM for affected versions of Cognos Analytics.
What versions of IBM Cognos Analytics are affected by CVE-2024-56340?
CVE-2024-56340 affects IBM Cognos Analytics versions 11.2.0 through 11.2.4 FP5.
Can CVE-2024-56340 be exploited remotely?
CVE-2024-56340 is a local file inclusion vulnerability that requires local access to exploit.
What is the impact of exploiting CVE-2024-56340?
Exploiting CVE-2024-56340 can allow attackers to access sensitive files on the server, leading to data breaches.