IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7179163 |
![]() ![]() |
History
Thu, 03 Jul 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Microsoft
Microsoft windows |
|
CPEs | cpe:2.3:a:ibm:cognos_controller:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Microsoft
Microsoft windows |
Tue, 07 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 07 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation. | |
Title | IBM Cognos Controller improper certificate validation | |
First Time appeared |
Ibm
Ibm cognos Controller Ibm controller |
|
Weaknesses | CWE-295 | |
CPEs | cpe:2.3:a:ibm:cognos_controller:11.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_controller:11.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm cognos Controller Ibm controller |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published: 2025-01-07T16:02:36.236Z
Updated: 2025-01-07T16:59:26.656Z
Reserved: 2024-07-08T19:31:12.238Z
Link: CVE-2024-40702

Updated: 2025-01-07T16:59:22.092Z

Status : Analyzed
Published: 2025-01-07T16:15:33.463
Modified: 2025-07-03T20:49:39.400
Link: CVE-2024-40702

No data.