# CVE-2024-25047

## Summary

- **CVE ID:** CVE-2024-25047
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N)
- **CWE:** CWE-117
- **Published:** May 2, 2024
- **Last Modified:** Mar 13, 2026

## Description

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This could lead to further attacks against the system.  IBM X-Force ID:  282956.

## Affected Products

- IBM — Cognos Analytics (11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2)

## References

- [CNA](https://www.ibm.com/support/pages/node/7149874)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/282956)
- [CNA](https://security.netapp.com/advisory/ntap-20240621-0007/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.64%
- **EPSS Percentile:** 49.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._