CVE-2019-4716

CVE Published 2019-12-18
Related CWE(s) CWE-94: Improper Control of Generation of Code ('Code Injection')
Related Vendor(s) ibm
Related Product(s) planning_analytics
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 10.0 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References