is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39343 | IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7177220 |
|
Tue, 03 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Dec 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Title | IBM Cognos Controller cross-site request forgery | |
| First Time appeared |
Ibm
Ibm cognos Controller |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:ibm:cognos_controller:11.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_controller:11.0.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm cognos Controller |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-12-03T17:55:03.583Z
Reserved: 2024-07-22T12:02:59.129Z
Link: CVE-2024-41776
Updated: 2024-12-03T17:49:32.268Z
Status : Analyzed
Published: 2024-12-03T18:15:14.107
Modified: 2024-12-11T03:24:19.023
Link: CVE-2024-41776
No data.
OpenCVE Enrichment
No data.
EUVD