Inclusion of Sensitive Information in Source Code in Cognos Analytics Mobile (iOS) - CVE-2024-55907

 

Inclusion of Sensitive Information in Source Code in Cognos Analytics Mobile (iOS) - CVE-2024-55907

Published: March 5, 2025


Vulnerability identifier: #VU105338
CSH Severity: Low
CVSS v4: 1 [CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-55907
CWE-ID: CWE-540
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to gain access to potentially sensitive information.

The vulnerability exists due to weak obfuscation. An attacker with physical access can reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used due to weak obfuscation.


Affected software

Cognos Analytics Mobile (iOS)

How to mitigate CVE-2024-55907

Install updates from vendor's website.

Cognos Analytics Mobile (iOS) - update to 1.1.21

External References

Related Security Bulletins