CVE-2020-4669: Critical severity IBM Planning Analytics Cloud vulnerability
IBM Planning Analtyics connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database.
Other sources
IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 184600.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-4669.
What is the severity of CVE-2020-4669?
The severity of CVE-2020-4669 is critical, with a severity value of 9.1.
What software is affected by CVE-2020-4669?
IBM Planning Analytics Cloud 2.0.0 and IBM Planning Analytics Local 2.0.0 are affected by CVE-2020-4669.
How does CVE-2020-4669 allow unauthorized access to the MongoDB server?
CVE-2020-4669 allows unauthorized access to the MongoDB server by allowing connections without password authentication.
Are there any references to learn more about CVE-2020-4669?
Yes, you can learn more about CVE-2020-4669 from the following references: [IBM X-Force ID: 184](https://exchange.xforce.ibmcloud.com/vulnerabilities/186400) and [IBM Support Pages](https://www.ibm.com/support/pages/node/6436821).