SB2025050106 - Multiple vulnerabilities in IBM Cognos Analytics



SB2025050106 - Multiple vulnerabilities in IBM Cognos Analytics

Published: May 1, 2025

Security Bulletin ID SB2025050106
Severity
Critical
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 50% High 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Arbitrary file upload (CVE-ID: CVE-2024-40695)

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to application does not validate the content of the file uploaded to the web interface. A remote user can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.


2) Improper Neutralization of Special Elements used in an Expression Language Statement (CVE-ID: CVE-2024-51466)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to Expression Language (EL) Injection. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, and/or cause the server to crash when using a specially crafted EL statement.


Remediation

Install update from vendor's website.