# CVE-2024-40684

## Summary

- **CVE ID:** CVE-2024-40684
- **Severity:** MEDIUM
- **CVSS Score:** 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-521
- **Published:** May 27, 2026
- **Last Modified:** May 27, 2026

## Description

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

## Affected Products

- IBM — Operations Analytics - Log Analysis (1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3)
- IBM — Operations Analytics - Log Analysis (1.3.6.0, 1.3.6.1)
- IBM — Operations Analytics - Log Analysis (1.3.7.0, 1.3.7.1, 1.3.7.2)
- IBM — Operations Analytics - Log Analysis (1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4)

## References

- [CNA](https://www.ibm.com/support/pages/node/7268536)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.36%
- **EPSS Percentile:** 29.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._