First published: Fri Feb 18 2022(Updated: )
IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into including remote files with malicious code. IBM X-Force ID: 216891.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Planning Analytics | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-22308.
The severity of CVE-2022-22308 is high (CVSS score: 7.8).
The affected software is IBM Planning Analytics 2.0.
To mitigate CVE-2022-22308, apply the latest security patches provided by IBM and follow the guidance provided in their support page.
You can find more information about CVE-2022-22308 in the IBM X-Force ID: 216891 and in their support page.