CVE-2019-4716: critical vulnerability in IBM Planning Analytics
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
IBM Planning Analytics allows anyone to log in as an administrator without a password and run dangerous commands with the highest system permissions. This is a critical flaw that gives complete control of the system to attackers.
An unauthenticated attacker can exploit a configuration overwrite vulnerability to gain admin credentials, then leverage TM1 scripting functionality to achieve remote code execution with root/SYSTEM privileges. The vulnerability affects versions 2.0.0 through 2.0.8 and requires no prior access or authentication.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.