Inclusion of Sensitive Information in Source Code in Cognos Analytics Mobile (iOS) - CVE-2024-55907

 

Inclusion of Sensitive Information in Source Code in Cognos Analytics Mobile (iOS) - CVE-2024-55907

Published: March 5, 2025


Vulnerability identifier: #VU105338
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-55907
CWE-ID: CWE-540
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: IBM Corporation
Affected software:
Cognos Analytics Mobile (iOS)

Detailed vulnerability description

The vulnerability allows an attacker with physical access to gain access to potentially sensitive information.

The vulnerability exists due to weak obfuscation. An attacker with physical access can reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used due to weak obfuscation.


How to mitigate CVE-2024-55907

Install updates from vendor's website.

Sources