CVE-2024-56344 PUBLISHED

IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vulnerabilities

Assigner: ibm
Reserved: 20.12.2024 Published: 18.09.2026 Updated: 18.09.2026

IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 5.9

Product Status

Vendor IBM
Product Cognos Analytics
Versions
  • affected from 12.0.4 to 12.0.4 FP2 (incl.)
  • affected from 12.1.0 to 12.1.3 FP1 (incl.)

Solutions

Affected Product(s)Version(s)Fix VersionIBM Cognos Analytics12.0.4 12.0.4 FP3 https://www.ibm.com/support/pages/node/7283969 IBM Cognos Analytics12.1.3 12.1.3 FP2 https://www.ibm.com/support/pages/node/7269268

References

Problem Types

  • CWE-327 Use of a Broken or Risky Cryptographic Algorithm CWE