Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2025-0064

Published Feb 21, 2025·Last modified Feb 21, 2025
Description
Feiten

IBM heeft kwetsbaarheden verholpen in IBM Cognos Controller (Versies 11.0.0 tot 11.0.1 FP3 en 11.1.0).

Interpretaties

De kwetsbaarheden stellen een kwaadwillende in staat om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Denial-of-Service (DoS)
  • Cross-Site-Scripting (XSS)
  • Omzeilen van een beveiligingsmaatregel
  • Manipulatie van gegevens
  • Verkrijgen van verhoogde rechten
  • Uitvoer van willekeurige code (Gebruikersrechten)
  • Toegang tot gevoelige informatie

De kwetsbaarheden bevinden zich zowel in de Cognos Controller-Applicatie zelf, als in onderliggende producten, zoals Java, Websphere Liberty, Apache Ant en diverse Open Source componenten, welke met Cognos Controller worden meegeleverd.

Oplossingen

IBM heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-130

Improper Handling of Length Parameter Inconsistency

CWE-399

CWE-399

CWE-379

Creation of Temporary File in Directory with Insecure Permissions

CWE-300

Channel Accessible by Non-Endpoint

CWE-798

Use of Hard-coded Credentials

CWE-284

Improper Access Control

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CWE-295

Improper Certificate Validation

CWE-91

XML Injection (aka Blind XPath Injection)

CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling

CWE-502

Deserialization of Untrusted Data

CWE-377

Insecure Temporary File

CWE-863

Incorrect Authorization

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-611

Improper Restriction of XML External Entity Reference

CWE-787

Out-of-bounds Write

CWE-20

Improper Input Validation

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard