#VU101323 Use of hard-coded credentials in IBM Cognos Controller - CVE-2024-41777
Published: December 6, 2024
IBM Cognos Controller
IBM Corporation
Description
The vulnerability allows a remote attacker to gain full access to vulnerable system.
The vulnerability exists due to IBM Cognos Controller contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. A remote unauthenticated attacker can access the affected system using the hard-coded credentials.