VYPR
High severity8.6NVD Advisory· Published May 2, 2024· Updated Jun 17, 2026

CVE-2024-25047

CVE-2024-25047

Description

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system. IBM X-Force ID: 282956.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:*range: >=11.2.0,<11.2.4
    • cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*
    • cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:*
    • cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:*
    • (no CPE)range: 11.2.0 - 11.2.4, 12.0.0 - 12.0.2
    • (no CPE)range: 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2
  • cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.