CVE-2024-45084

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.
References
Link Resource
https://www.ibm.com/support/pages/node/7183597 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:cognos_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:controller:11.1.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-02-19 16:15

Updated : 2025-09-29 18:15


NVD link : CVE-2024-45084

Mitre link : CVE-2024-45084

CVE.ORG link : CVE-2024-45084


JSON object : View

Products Affected

microsoft

  • windows

ibm

  • controller
  • cognos_controller
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File