CVE-2024-56340
MEDIUMDescription
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
Is your site exposed to CVE-2024-56340?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | cognos_analytics |
| ibm | cognos_analytics |
| ibm | cognos_analytics |
| ibm | cognos_analytics |
| ibm | cognos_analytics |
| ibm | cognos_analytics |
| ibm | cognos_analytics |
| ibm | cognos_analytics |
| ibm | cognos_analytics |
| ibm | cognos_analytics |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-56340? +
How severe is CVE-2024-56340? +
What products are affected by CVE-2024-56340? +
How do I check if I'm vulnerable to CVE-2024-56340? +
Related Vulnerabilities
Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. The application …
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values …
The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read …
Collabora Online is a collaborative online office suite based on LibreOffice technology. In versions prior to 24.04.12.4, 23.05.19, and 22.05.25, …
Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$target` parameter in `/controller.php` was not …
If exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccessible