Executive brief
IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated attacker to log in as 'admin'. Once authenticated, the attacker can execute arbitrary code with root or SYSTEM privileges via TM1 scripting.
Affected products
- IBM Planning Analytics 2.0.0 through 2.0.8
Timeline
- 2019-12-18: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog