CISA Known Exploited Vulnerability

CVE-2019-4716

IBM · Planning Analytics

IBM Planning Analytics Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-94
Ransomware Unknown

CISA description

IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.

Required action

Apply updates per vendor instructions.