Skip to main content

Insufficient Type Distinction

CVE-2024-45676

Severity Medium
Score 4.3/10

Summary

IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insufficient file type distinction.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • LOW
  • NONE
  • NONE

CWE-351 - Insufficient Type Distinction

The software does not properly distinguish between different types of elements in a way that leads to insecure behavior.

References

Advisory Timeline

  • Published