CVE-2024-45084 – IBM Cognos Controller Formula Injection Vulnerability

The following table lists the changes that have been made to the
CVE-2024-45084 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 19, 2025

    Action Type Old Value New Value
    Added Description IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0

    could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.

    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
    Added CWE CWE-502
    Added Reference https://www.ibm.com/support/pages/node/7183597
Share the Post:

Related Posts