CVE-2024-45084
published 2025-02-19CVE-2024-45084: IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could…
PriorityP345high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
0.40%
32.8th percentile
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | cognos_controller | >= 11.0.0 < 11.0.1.4 | 11.0.1.4 |
| ibm | cognos_controller | 11.0.0 – 11.0.1 | — |
| ibm | controller | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
ghsa·2026-04-24
CVE-2026-41486 [HIGH] CWE-502 Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
Ray Data registers custom Arrow extension types (`ray.data.arrow_tensor`, `ray.data.arrow_tensor_v2`, `ray.data.arrow_variable_shaped_tensor`) globally in PyArrow. When PyArrow reads a Parquet file containing one of these extension types, it calls `__arrow_ext_deserialize__` on the field's metadata bytes. Ray's implementation passes these bytes directly to `cloudpickle.loads()`, achieving arbitrary code execution during schema parsing, before any row data is read.
In May 2024, Ray fixed a related vulnerability in `PyExtensionType`-based extension types ([issue #41314](https://github.com/ray-project/ray/issues/41314), [PR #45084](https://github.com/ray-project/ray/pull/45084)). In July 2025, [PR #54831](https://gi
GHSA
GHSA-658q-f487-r8h7: IBM Cognos Controller 11
ghsa_unreviewed·2025-02-19
CVE-2024-45084 [HIGH] CWE-1236 GHSA-658q-f487-r8h7: IBM Cognos Controller 11
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-19
Published