CVE-2024-40703: IBM Cognos Analytics
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.
Affected products
- IBM Cognos Analytics: from 11.2.0, up to and including 11.2.3; from 12.0.0, before 12.0.3 (fixed in 12.0.3); version 11.2.4 only; version 12.0.3 only
- IBM Cognos Analytics Reports: version 11.0.0.7 only
Published 2024-09-22. Last modified 2026-06-17.