Vulnerability Description
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Cognos Analytics | >= 11.2.0, <= 11.2.3 |
| Ibm | Cognos Analytics Reports | 11.0.0.7 |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7160700PatchVendor Advisory
- https://www.ibm.com/support/pages/node/7168038PatchVendor Advisory
FAQ
What is CVE-2024-40703?
CVE-2024-40703 is a vulnerability with a CVSS score of 5.5 (MEDIUM). IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive informat...
How severe is CVE-2024-40703?
CVE-2024-40703 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-40703?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Cognos Analytics, Ibm Cognos Analytics Reports.