IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are vulnerable to a cross-site request forgery (CSRF) vulnerability that could allow an attacker to trick a trusted user into performing unauthorized actions.
History

Wed, 04 Feb 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are vulnerable to a cross-site request forgery (CSRF) vulnerability that could allow an attacker to trick a trusted user into performing unauthorized actions.
Title IBM Operations Analytics - Log Analysis is affected by CSRF Token Replay Attack
First Time appeared Ibm
Ibm operations Analytics - Log Analysis
Weaknesses CWE-352
CPEs cpe:2.3:a:ibm:operations_analytics_-_log_analysis:1.3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_-_log_analysis:1.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_-_log_analysis:1.3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_-_log_analysis:1.3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_-_log_analysis:1.3.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_-_log_analysis:1.3.7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_-_log_analysis:1.3.7.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_-_log_analysis:1.3.7.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_-_log_analysis:1.3.8.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_-_log_analysis:1.3.8.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_-_log_analysis:1.3.8.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:operations_analytics_-_log_analysis:1.3.8.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm operations Analytics - Log Analysis
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-02-04T21:12:46.729Z

Updated: 2026-02-04T21:13:34.099Z

Reserved: 2024-07-08T19:30:52.530Z

Link: CVE-2024-40685

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-04T22:15:56.500

Modified: 2026-02-04T22:15:56.500

Link: CVE-2024-40685

cve-icon Redhat

No data.