CVE-2025-33004: IBM Planning Analytics Local path traversal
IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.
Other sources
IBM Planning Analytics Local could allow a privileged user to delete files from directories due to improper pathname restriction.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33004?
CVE-2025-33004 has a high severity due to the potential for unauthorized file deletion by privileged users.
How do I fix CVE-2025-33004?
To fix CVE-2025-33004, upgrade IBM Planning Analytics Local to version 2.2 or later to address the improper pathname restriction.
Who is affected by CVE-2025-33004?
CVE-2025-33004 affects IBM Planning Analytics Local versions 2.0 and 2.1.
What kind of vulnerability is CVE-2025-33004?
CVE-2025-33004 is a file deletion vulnerability caused by improper pathname restrictions for privileged users.
Can CVE-2025-33004 lead to data loss?
Yes, CVE-2025-33004 can lead to data loss if a privileged user deletes critical files from the affected directories.