#VU105338 Inclusion of Sensitive Information in Source Code in Cognos Analytics Mobile (iOS) - CVE-2024-55907

 

#VU105338 Inclusion of Sensitive Information in Source Code in Cognos Analytics Mobile (iOS) - CVE-2024-55907

Published: March 5, 2025


Vulnerability identifier: #VU105338
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-55907
CWE-ID: CWE-540
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Cognos Analytics Mobile (iOS)
Software vendor:
IBM Corporation

Description

The vulnerability allows an attacker with physical access to gain access to potentially sensitive information.

The vulnerability exists due to weak obfuscation. An attacker with physical access can reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used due to weak obfuscation.


Remediation

Install updates from vendor's website.

External links