Description
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
CVSS breakdown
CVSS 3.0
User Interaction
None
Attack Complexity
Low
Privileges Required
None
Integrity
High
Scope
Changed
Attack Vector
Network
Confidentiality
High
Availability
High
RC
Changed
RL
O
E
Unchanged
Affected products
- ibm / planning_analytics2.0.0 – 2.0.0
- ibm / planning_analytics2.0.8 – 2.0.8
Exploits & proofs of concept
References
- MISChttps://www.ibm.com/support/pages/node/1127781
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/172094
- MAILING_LISThttp://seclists.org/fulldisclosure/2020/Mar/44
- EXPLOIThttp://packetstormsecurity.com/files/156953/IBM-Cognos-TM1-IBM-Planning-Analytics-Server-Configuration-Overwrite-Code-Execution.html
Updated 14m ago · 8 sources