CVE-2024-40695
IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and
12.0.0 through 12.0.4
could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.42%
- Percentil entre todas las CVEs puntuadas: 34
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution75 % - Impacto principal
T1505.003Web Shellpersistence80 % - Impacto secundario
T1059Command and Scripting Interpreterexecution70 %
CWE-434 (subida de fichero malicioso) con UI:R indica interacción del usuario. La carga de ficheros ejecutables en la interfaz web de Cognos permite web shells (T1505.003) y ejecución de código posterior (T1059).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-434
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-40695",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-40695",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-12-20T15:41:48.274181Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@us.ibm.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:ibm:cognos_analytics:11.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:cognos_analytics:11.2.1:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:cognos_analytics:11.2.2:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:cognos_analytics:11.2.3:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:cognos_analytics:11.2.4:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:cognos_analytics:12.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:cognos_analytics:12.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:cognos_analytics:12.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:cognos_analytics:12.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:cognos_analytics:12.0.4:*:*:*:*:*:*:*"
],
"vendor": "IBM",
"product": "Cognos Analytics",
"versions": [
{
"status": "affected",
"version": "11.2.0",
"versionType": "semver",
"lessThanOrEqual": "11.2.4"
},
{
"status": "affected",
"version": "12.0.0",
"versionType": "semver",
"lessThanOrEqual": "12.0.4"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-12-20T14:15:24.063",
"references": [
{
"url": "https://www.ibm.com/support/pages/node/7179496",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@us.ibm.com",
"description": [
{
"lang": "en",
"value": "CWE-434"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and \n\n12.0.0 through 12.0.4\n\n\n\ncould be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks."
},
{
"lang": "es",
"value": "IBM Cognos Analytics 11.2.0 a 11.2.4 FP4 y 12.0.0 a 12.0.4 podrían ser vulnerables a la carga de archivos maliciosos al no validar el contenido del archivo cargado en la interfaz web. Los atacantes pueden aprovechar esta debilidad y cargar archivos ejecutables maliciosos en el sistema, que pueden enviarse a la víctima para realizar otros ataques."
}
],
"lastModified": "2026-06-17T07:46:22.117",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA7F561D-2D45-4BDB-AE84-1BD057DC9930",
"versionEndExcluding": "11.2.4",
"versionStartIncluding": "11.2.0"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90D7AA5F-889B-4FC6-AE9D-9659FCAC13FF",
"versionEndExcluding": "12.0.4",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1D81212-AFFE-4A73-AAC1-E558973FC452"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07DC144D-62FC-4808-A77A-642871C1F8FC"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A61B920-B490-48A8-BF00-13B8854683FD"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F65BC6D-9A9D-45B9-919B-2855586C4F1B"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "684FA3C7-ABEA-4CB8-8D88-4BA18F1A73FB"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_analytics:12.0.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CED100CC-0C88-41B9-8742-4AD51C105527"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}