CVE-2024-45084
HIGHDescription
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.
Is your site exposed to CVE-2024-45084?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | cognos_controller |
| ibm | controller |
| microsoft | windows |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-45084? +
How severe is CVE-2024-45084? +
What products are affected by CVE-2024-45084? +
How do I check if I'm vulnerable to CVE-2024-45084? +
Related Vulnerabilities
Data provided in a request performed to the server while activating a new device are put in a database. Other …
In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation …
phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LDAP directory …
Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, …
There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data …
A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying …