CVE-2024-40702: IBM Cognos Controller

High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.

Affected products

  • IBM Cognos Controller: from 11.0.0, up to and including 11.0.1
  • IBM Controller: version 11.1.0 only

Published 2025-01-07. Last modified 2026-06-17.