CVE-2024-56340: IBM Cognos Analytics
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
Affected products
- IBM Cognos Analytics: from 11.2.0, before 11.2.4 (fixed in 11.2.4); from 12.0.0, before 12.0.4 (fixed in 12.0.4); version 11.2.4 only; version 12.0.4 only
Published 2025-02-28. Last modified 2026-06-17.