CVE-2021-39040: Malicious File Upload
IBM Planning Analytics could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks.
Other sources
IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 214025.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-39040.
What is the severity level of CVE-2021-39040?
The severity level of CVE-2021-39040 is high.
What is the impact of the vulnerability?
The vulnerability allows attackers to upload malicious executable files into the system and perform further attacks.
What is the affected software?
The affected software is IBM Planning Analytics Workspace 2.0.
How can I fix this vulnerability?
To fix this vulnerability, IBM Planning Analytics Workspace should implement file type and size validation during file uploads.