IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.
CVE ID: CVE-2024-45084
CVSS Base Severity: HIGH
CVSS Base Score: 8.0
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vendor: IBM
Product: Cognos Controller
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 10.94% (scored less or equal to compared to others)
EPSS Date: 2025-03-20 (when was this score calculated)