CVE-2020-4670: Critical severity ibm planning analytics vulnerability
IBM Planning Analytics connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server.
Other sources
IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server. IBM X-Force ID: 186401.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4670?
The severity of CVE-2020-4670 is critical, with a CVSS score of 9.1.
What is the affected software for CVE-2020-4670?
The affected software for CVE-2020-4670 includes IBM Planning Analytics Cloud 2.0.0 and IBM Planning Analytics Local 2.0.0.
How can a remote attacker exploit CVE-2020-4670?
A remote attacker can exploit CVE-2020-4670 by gaining unauthorized access to the unprotected Redis server.
Is there a fix available for CVE-2020-4670?
Yes, a fix is provided by IBM. Please refer to the official IBM support pages for details on how to apply the fix.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-4670?
The Common Weakness Enumeration (CWE) ID for CVE-2020-4670 is 306.