First published: Fri May 14 2021(Updated: )
IBM Planning Analtyics connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Planning Analytics Cloud | =2.0.0 | |
IBM Planning Analytics Local | =2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-4669.
The severity of CVE-2020-4669 is critical, with a severity value of 9.1.
IBM Planning Analytics Cloud 2.0.0 and IBM Planning Analytics Local 2.0.0 are affected by CVE-2020-4669.
CVE-2020-4669 allows unauthorized access to the MongoDB server by allowing connections without password authentication.
Yes, you can learn more about CVE-2020-4669 from the following references: [IBM X-Force ID: 184](https://exchange.xforce.ibmcloud.com/vulnerabilities/186400) and [IBM Support Pages](https://www.ibm.com/support/pages/node/6436821).