First published: Wed Dec 18 2019(Updated: )
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Planning Analytics | >=2.0<=2.0.8 | |
IBM Planning Analytics | ||
>=2.0<=2.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4716 is a remote code execution vulnerability in IBM Planning Analytics that allows an unauthenticated user to login as "admin" and execute code as root or SYSTEM.
CVE-2019-4716 has a severity score of 9.8 (Critical).
IBM Planning Analytics versions 2.0.0 through 2.0.8 are affected by CVE-2019-4716.
An attacker can exploit CVE-2019-4716 by overwriting a configuration, logging in as "admin", and executing code as root or SYSTEM via TM1 scripting.
You can find more information about CVE-2019-4716 on the IBM X-Force ID: 172094, Packet Storm Security, and Full Disclosure websites.