CVE-2024-49352XML External Entity (XXE) Injection in IBM Cognos Analytics

Severity
7.1HIGHNVD
EPSS
0.2%
top 58.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 5

Description

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:LExploitability: 2.8 | Impact: 4.2

Affected Packages2 packages

NVDibm/cognos_analytics11.2.011.2.4+3
CVEListV5ibm/cognos_analytics11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4

Patches

🔴Vulnerability Details

2
CVEList
IBM Cognos Anaytics XML external entity injection2025-02-05
GHSA
GHSA-f3j9-rq93-g9jv: IBM Cognos Analytics 112025-02-05
CVE-2024-49352 — XML External Entity (XXE) Injection | cvebase