CVE-2019-4716: IBM Planning Analytics Remote Code Execution Vulnerability
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
Other sources
IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-4716?
CVE-2019-4716 is a remote code execution vulnerability in IBM Planning Analytics that allows an unauthenticated user to login as "admin" and execute code as root or SYSTEM.
How severe is CVE-2019-4716?
CVE-2019-4716 has a severity score of 9.8 (Critical).
What software versions are affected by CVE-2019-4716?
IBM Planning Analytics versions 2.0.0 through 2.0.8 are affected by CVE-2019-4716.
How can an attacker exploit CVE-2019-4716?
An attacker can exploit CVE-2019-4716 by overwriting a configuration, logging in as "admin", and executing code as root or SYSTEM via TM1 scripting.
Where can I find more information about CVE-2019-4716?
You can find more information about CVE-2019-4716 on the IBM X-Force ID: 172094, Packet Storm Security, and Full Disclosure websites.