Skip to content
ibmCVE-2024-56344

IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.

Medium5.9CVE-2024-56344 · Published Sep 18, 2026 · updated Sep 19, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Cognos Analytics
Vendor
>= 12.0.4, <= 12.0.4 FP2No fix yet
>= 12.1.0, <= 12.1.3 FP1No fix yet
Details and references

IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
no source yet
Weakness
CWE-327

More ibm advisories

All

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.