Home / Vulnerabilities / CVE-2019-4716
CRITICAL SEVERITY
CVE-2019-4716 IBM · Planning Analytics

IBM Planning Analytics Remote Code Execution Vulnerability

Technical Severity

CVSS v3.1 Metrics

CRITICAL
10 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.0/UI:N/AC:L/PR:N/I:H/S:C/AV:N/C:H/A:H/RC:C/RL:O/E:U
Exploitation Likelihood

EPSS Prediction

91.53 %
Predictive Probability
Percentile Rank
99.7 th

Documented as more likely to be exploited than 99.7% of known CVEs.

Detection Date

Nov 03, 2021

Remediation Due

May 03, 2022

CISA Catalog Active

Threat Analysis

IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.

Remediation Directive

Apply updates per vendor instructions.

External Intelligence