CVE-2024-25047
Estado: AnalizadaAlta (8.6)—
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- Puntuación base: 8.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.64%
- Percentil entre todas las CVEs puntuadas: 49
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-117
Referencias
- https://exchange.xforce.ibmcloud.com/vulnerabilities/282956
- https://security.netapp.com/advisory/ntap-20240621-0007/
- https://www.ibm.com/support/pages/node/7149874
- https://exchange.xforce.ibmcloud.com/vulnerabilities/282956
- https://security.netapp.com/advisory/ntap-20240621-0007/
- https://www.ibm.com/support/pages/node/7149874
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-25047",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-25047",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-05-09T16:08:03.801871Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@us.ibm.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "IBM",
"product": "Cognos Analytics",
"versions": [
{
"status": "affected",
"version": "11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*"
],
"vendor": "ibm",
"product": "cognos_analytics",
"versions": [
{
"status": "affected",
"version": "11.2.0 <= 11.2.4, 12.0.0 <= 12.0.2"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-05-02T21:16:11.330",
"references": [
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/282956",
"tags": [
"VDB Entry",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "https://security.netapp.com/advisory/ntap-20240621-0007/",
"tags": [
"Third Party Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "https://www.ibm.com/support/pages/node/7149874",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/282956",
"tags": [
"VDB Entry",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20240621-0007/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.ibm.com/support/pages/node/7149874",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@us.ibm.com",
"description": [
{
"lang": "en",
"value": "CWE-117"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956."
},
{
"lang": "es",
"value": "IBM Cognos Analytics 11.2.0 a 11.2.4 y 12.0.0 a 12.0.2 es vulnerable a ataques de inyección en el registro de aplicaciones al no sanitizar los datos proporcionados por el usuario. Esto podría dar lugar a nuevos ataques contra el sistema. ID de IBM X-Force: 282956."
}
],
"lastModified": "2026-06-17T07:15:25.333",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA7F561D-2D45-4BDB-AE84-1BD057DC9930",
"versionEndExcluding": "11.2.4",
"versionStartIncluding": "11.2.0"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A68167C-53E1-4785-A86C-19414F1F25A8",
"versionEndExcluding": "12.0.3",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1D81212-AFFE-4A73-AAC1-E558973FC452"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07DC144D-62FC-4808-A77A-642871C1F8FC"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A61B920-B490-48A8-BF00-13B8854683FD"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F1BE6C1F-2565-4E97-92AA-16563E5660A5"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}