SB2025050106 - Multiple vulnerabilities in IBM Cognos Analytics
Published: May 1, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Arbitrary file upload (CVE-ID: CVE-2024-40695)
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to application does not validate the content of the file uploaded to the web interface. A remote user can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.
2) Improper Neutralization of Special Elements used in an Expression Language Statement (CVE-ID: CVE-2024-51466)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to Expression Language (EL) Injection. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, and/or cause the server to crash when using a specially crafted EL statement.
Remediation
Install update from vendor's website.