V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2024-56340
CVE
MediumConfirmedExploit available

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitiv…

CVSS
6.5
Medium
EPSS
0.12
p93
Published
2024-01-01
Updated
2024-01-01
Description

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.

Tags · CWE
CWE-23
CAPEC-76
CAPEC-139
Affected products
Cognos_analytics 11.2.0–11.2.4Cognos_analytics 12.0.0–12.0.4Cognos_analytics
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.122 · p93
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2024-56340
github-poc · https://github.com/MarioTesoro/CVE-2024-56340
Enterprise
Affected software
ProductVendorStatus
cognos_analytics*Tracked
Source databases
CVE