CVE-2024-45676
MEDIUMDescription
IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insufficient file type distinction.
Is your site exposed to CVE-2024-45676?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | cognos_controller |
| ibm | cognos_controller |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-45676? +
How severe is CVE-2024-45676? +
What products are affected by CVE-2024-45676? +
How do I check if I'm vulnerable to CVE-2024-45676? +
Related Vulnerabilities
skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain …
skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain …
Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. …
An attacker can upload an arbitrary file instead of a plant image.
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's …
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users …