IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization.
CVE ID: CVE-2024-28778
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.5
Vendor: IBM
Product: Controller
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 20.6% (scored less or equal to compared to others)
EPSS Date: 2025-02-05 (when was this score calculated)