CVE-2024-40695

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.
Configurations

No configuration.

History

20 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-20 14:15

Updated : 2024-12-20 14:15


NVD link : CVE-2024-40695

Mitre link : CVE-2024-40695

CVE.ORG link : CVE-2024-40695


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type