CVE-2024-28777 – IBM Cognos Controller Unrestricted Deserialization Vulnerability

The following table lists the changes that have been made to the
CVE-2024-28777 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 19, 2025

    Action Type Old Value New Value
    Added Description IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0

    is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate privileges, or cause denial of service attacks by exploiting the unrestricted deserialization of types in the application.

    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-502
    Added Reference https://www.ibm.com/support/pages/node/7183597
Share the Post:

Related Posts