First published: Fri Apr 22 2022(Updated: )
IBM Planning Analytics could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Planning Analytics Workspace | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-39040.
The severity level of CVE-2021-39040 is high.
The vulnerability allows attackers to upload malicious executable files into the system and perform further attacks.
The affected software is IBM Planning Analytics Workspace 2.0.
To fix this vulnerability, IBM Planning Analytics Workspace should implement file type and size validation during file uploads.