CVE-2024-51466

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/12/2024
Last modified:
02/07/2025

Description

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and <br /> <br /> 12.0.0 through 12.0.4<br /> <br /> is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, and/or cause the server to crash when using a specially crafted EL statement.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:* 11.2.0 (including) 11.2.4 (excluding)
cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:* 12.0.0 (including) 12.0.4 (excluding)
cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack3:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack4:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_analytics:12.0.4:-:*:*:*:*:*:*


References to Advisories, Solutions, and Tools