#VU101326 Authentication bypass using an alternate path or channel in IBM Cognos Controller - CVE-2024-25036


Vulnerability identifier: #VU101326

Vulnerability risk: Low

CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-25036

CWE-ID: CWE-288

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
IBM Cognos Controller
Client/Desktop applications / Other client software

Vendor: IBM Corporation

Description

The vulnerability allows a remote user to bypass security restrictions.

The vulnerability exists due to an alternate path or channel in the application. An authenticated user with local access can bypass security restrictions allowing users to circumvent restrictions imposed on input fields.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

IBM Cognos Controller: before 11.0.1.0.3


External links
https://www.ibm.com/support/pages/node/7177220


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability