← Vulnerability feed

Vulnerability record · CVE-2023-40695 · published 3 May 2024

CVE-2023-40695: Ibm cognos controller insufficient session expiration vulnerability

Ibm · Cognos Controller

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 264938.

8.8 CVSS 3.1 High EPSS 0.35% · top 73.8% CWE-613 · Insufficient session expiration
8.8CVSS 3.1 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 264938.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-40695 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-25020Ibm cognos controller unrestricted file upload vulnerabilityIBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Journal entry pag…EPSS 0.28%9.8CVE-2024-40691Ibm cognos controller unrestricted file upload vulnerabilityIBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web in…EPSS 0.37%9.8CVE-2024-25019Ibm cognos controller unrestricted file upload vulnerabilityIBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry att…EPSS 0.28%9.8CVE-2023-38724Ibm cognos controller sql injection vulnerabilityIBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which…EPSS 0.46%9.8CVE-2020-4877Ibm cognos controller incorrect authorization vulnerabilityIBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Fo…EPSS 0.90%9.8CVE-2020-4879Ibm cognos controller improper authentication vulnerabilityIBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of auth…EPSS 1.5%8.8CVE-2024-28777Ibm cognos controller deserialization of untrusted data vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows us…EPSS 0.61%8.8CVE-2024-52902Ibm cognos controller hard-coded credentials vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code wh…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2023-40695), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.