CVE-2024-51466: IBM Cognos Analytics expression language injection

9.0 CVSS

Description

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and

12.0.0 through 12.0.4

is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, and/or cause the server to crash when using a specially crafted EL statement.

Classification

CVE ID: CVE-2024-51466

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.0

Affected Products

Vendor: IBM

Product: Cognos Analytics

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.13% (probability of being exploited)

EPSS Percentile: 48.75% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://www.ibm.com/support/pages/node/7179496

Timeline