IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.
Conclusion & alert: CVE-2024-40695 is rated Moderate Risk (43.6/100): CVSS High severity, with low exploitation likelihood (EPSS 0.41%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.13% | 0.41% | +0.28% |
| 2 | 2025-11-21 | 0.42% | 0.13% | -0.29% |
| 3 | 2025-11-18 | — | 0.42% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.0 | 3.1 | HIGH |
|
2.1 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| ibm | cognos_analytics | >= 11.2.0, < 11.2.4 | cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:* |
| ibm | cognos_analytics | >= 12.0.0, < 12.0.4 | cpe:2.3:a:ibm:cognos_analytics:*:*:*:*:*:*:*:* |
| ibm | cognos_analytics | 11.2.4 | cpe:2.3:a:ibm:cognos_analytics:11.2.4:-:*:*:*:*:*:* |
| ibm | cognos_analytics | 11.2.4 | cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack1:*:*:*:*:*:* |
| ibm | cognos_analytics | 11.2.4 | cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack2:*:*:*:*:*:* |
| ibm | cognos_analytics | 11.2.4 | cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack3:*:*:*:*:*:* |
| ibm | cognos_analytics | 11.2.4 | cpe:2.3:a:ibm:cognos_analytics:11.2.4:fixpack4:*:*:*:*:*:* |
| ibm | cognos_analytics | 12.0.4 | cpe:2.3:a:ibm:cognos_analytics:12.0.4:-:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.ibm.com/support/pages/node/7179496 | Patch Vendor Advisory |