Vulnerabilities > IBM > Cognos Controller > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-12-03 CVE-2024-25020 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Cognos Controller 11.0.0/11.0.1
IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Journal entry page.
network
low complexity
ibm CWE-434
critical
9.8
2024-12-03 CVE-2024-40691 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Cognos Controller 11.0.0/11.0.1
IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.
network
low complexity
ibm CWE-434
critical
9.8
2024-12-03 CVE-2024-25019 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Cognos Controller 11.0.0/11.0.1
IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry attachments.
network
low complexity
ibm CWE-434
critical
9.8
2024-05-03 CVE-2023-38724 Unspecified vulnerability in IBM Cognos Controller 10.4.1/10.4.2/11.0.0
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection.
network
low complexity
ibm
critical
9.8
2022-01-21 CVE-2020-4879 Improper Authentication vulnerability in IBM Cognos Controller 10.4.0/10.4.1/10.4.2
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies.
network
low complexity
ibm CWE-287
critical
9.8
2022-01-21 CVE-2020-4877 Incorrect Authorization vulnerability in IBM Cognos Controller 10.4.0/10.4.1/10.4.2
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes.
network
low complexity
ibm CWE-863
critical
9.8