Description
IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server. IBM X-Force ID: 186401.
CVSS breakdown
CVSS 3.0
Privileges Required
None
Attack Complexity
High
Scope
Unchanged
Attack Vector
Network
User Interaction
None
Confidentiality
High
Availability
None
Integrity
High
RC
Changed
E
Unchanged
RL
O
Affected products
- ibm / planning_analytics_local2.0 – 2.0