Cyber Posture

CVE-2024-49352

High

Published: 05 February 2025

Published
05 February 2025
Modified
02 July 2025
KEV Added
Patch
CVSS Score 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
EPSS Score 0.0020 41.3th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Description

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Security Summary

IBM Cognos Analytics versions 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 are affected by CVE-2024-49352, an XML External Entity Injection (XXE) vulnerability classified under CWE-611. This flaw occurs when the software processes XML data, enabling potential exploitation during XML parsing operations. The vulnerability carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L), indicating high confidentiality impact with low availability impact.

A remote attacker with low privileges (PR:L) can exploit this vulnerability over the network with low complexity and no user interaction required. Successful exploitation allows the attacker to disclose sensitive information from the server or consume memory resources, leading to denial-of-service conditions.

IBM has published a security advisory at https://www.ibm.com/support/pages/node/7181480 providing details on the vulnerability, affected versions, and recommended mitigation steps, including available patches.

Details

CWE(s)
CWE-611

Affected Products

ibm
cognos analytics
11.2.4, 12.0.4 · 11.2.0 — 11.2.4 · 12.0.0 — 12.0.4

References