Summary An exposed API key in IBM Cognos Analytics could allow an unauthorized attacker to send unsolicited push notification alerts to IBM Cognos Analytics Reports mobile client applications. IBM Cognos Analytics has addressed the applicable CVE by revoking the exposed API key. Revocation of this API key will cause push notifications to cease functioning for mobile users of the IBM Cognos Analytics Reports applications. These fixes include a new encrypted API key that will be required to restore functionality to notifications on mobile devices. Vulnerability Details ** CVEID: CVE-2024-40703 DESCRIPTION: **IBM Cognos Analytics could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications. CVSS Base score: 6.2 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/298220 for the current score. CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) Affected Products and Versions Affected Product(s)| Version(s) —|— IBM Cognos Analytics Reports (iOS)| 11.0.0.7 Remediation/Fixes Affected Product| Affected Version| Fix —|—|— IBM Cognos Analytics Reports (iOS)| 11.0.0.7| IBM Cognos Analytics Reports Version 11.0.0.7 Build 11.7.59 In order to completely apply this fix, users must update both their IBM Cognos Analytics instance and IBM Cognos Analytics Reports mobile client applications. Security Bulletin: IBM Cognos…Read More
References
Back to Main