CVE-2019-4716criticalunder attackCWE-94

CVE-2019-4716: critical vulnerability in IBM Planning Analytics

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 10epss 86%
from disclosure to weapon104 days
Published on NVDDec 18
1st PoC+104d
metasploit+1d
CISA KEV+686d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

IBM Planning Analytics allows anyone to log in as an administrator without a password and run dangerous commands with the highest system permissions. This is a critical flaw that gives complete control of the system to attackers.

Technical detail

An unauthenticated attacker can exploit a configuration overwrite vulnerability to gain admin credentials, then leverage TM1 scripting functionality to achieve remote code execution with root/SYSTEM privileges. The vulnerability affects versions 2.0.0 through 2.0.8 and requires no prior access or authentication.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
CVSS:3.0/UI:N/AC:L/PR:N/I:H/S:C/AV:N/C:H/A:H/RC:C/RL:O/E:U
Affected products
IBM · Planning Analytics
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.