CVE-2024-56340 Details
Description
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
A local file inclusion vulnerability has been identified in IBM Cognos Analytics versions 11.2.0 through 11.2.4 FP5. This vulnerability allows an attacker to access sensitive files by inserting path traversal payloads into the deficon parameter.
Users are advised to upgrade to IBM Cognos Analytics 11.2.4 IF4. Instructions for upgrading can be found on the IBM Support page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MarioTesoro/vulnerability-research/tree/main/CVE-2024-56340 | CVE | |
| https://www.ibm.com/support/pages/node/7183676 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-23 | Relative Path Traversal | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm cognos analytics | >= 11.2.0, < 11.2.4 >= 12.0.0, < 12.0.4 11.2.4 - 11.2.4 fixpack1 11.2.4 fixpack2 11.2.4 fixpack3 11.2.4 fixpack4 11.2.4 fixpack5 12.0.4 - 12.0.4 interim_fix_1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 17, 2025 | CVE Modified | CVE |
| Jul 2, 2025 | Initial Analysis | [email protected] |
| Feb 28, 2025 | New CVE Received | [email protected] |