IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.
History

Wed, 19 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Feb 2025 15:00:00 +0000

Type Values Removed Values Added
Description IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.
Title IBM Cognos Controller information disclosure
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-02-19T14:50:24.376Z

Updated: 2025-02-19T15:26:06.517Z

Reserved: 2024-11-17T14:25:57.179Z

Link: CVE-2024-52902

cve-icon Vulnrichment

Updated: 2025-02-19T15:25:32.331Z

cve-icon NVD

Status : Received

Published: 2025-02-19T15:15:14.660

Modified: 2025-02-19T15:15:14.660

Link: CVE-2024-52902

cve-icon Redhat

No data.