CRITICAL🇵🇱 Wersja polska

CVE-2024-51466

CVSS 9.0v3.1pub. 2024-12-20upd. 2025-07-02

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, and/or cause the server to crash when using a specially crafted EL statement.

🤖 AI Analysis
How it works

The vulnerability (CWE-917) consists of the ability to inject a crafted EL expression, which is then interpreted and executed by the application engine on the server side. An attacker sends a specially constructed request containing a malicious EL expression, bypassing data input validation mechanisms. Execution of such an expression can lead to reading confidential data, excessive memory consumption, or causing the server to enter a denial of service state (crash).

Impact

An attacker can gain access to sensitive information processed by the server, exhaust operational memory resources, or cause IBM Cognos Analytics server to crash, resulting in service unavailability.

Mitigation & patch

Apply patches available from the vendor according to references published by IBM at: https://www.ibm.com/support/pages/node/7179496

Who is affected

IBM Cognos Analytics versions 11.2.0 to 11.2.4 FP4 and 12.0.0 to 12.0.4

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • IBM Cognos Analytics

    APP
    Ibm
    11.2.412.0.411.2.0 – 11.2.4 (excl.)12.0.0 – 12.0.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-38945CRITICAL9.8PL ✓same product

IBM Cognos Analytics — nieograniczony upload plików (CWE-434)

CVE-2020-4561CRITICAL10.0PL ✓same product

IBM Cognos Analytics – nieuwierzytelniony dostęp do DQM API (odczyt/zapis plików)

CVE-2020-4377CRITICAL9.1PL ✓same product

IBM Cognos Analytics — atak XXE umożliwiający wyciek danych

CVE-2025-25032HIGH7.5same product

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could ...

CVE-2024-49352HIGH7.1same product

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vul...