Junglewise Threat Intelligence

CVE-2019-4716: IBM Planning Analytics Remote Code Execution Vulnerability

CVE-2019-4716 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: IBM.

Executive brief

IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated attacker to log in as 'admin'. Once authenticated, the attacker can execute arbitrary code with root or SYSTEM privileges via TM1 scripting.

Affected products

  • IBM Planning Analytics 2.0.0 through 2.0.8

Timeline

  • 2019-12-18: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog