CVE-2019-4716
KEV PoC ×2moderateUnauthenticated RCE in IBM Planning Analytics 2.0
CISA: IBM Planning Analytics Remote Code Execution Vulnerability
IBM Planning Analytics 2.0.0 through 2.0.8 contains a configuration overwrite flaw that allows an unauthenticated remote attacker to log in as the 'admin' account. Once authenticated as admin, the attacker can execute arbitrary code via TM1 scripting, running as root on Linux servers or as SYSTEM on Windows. Exploitation requires only network access to the vulnerable service, with no credentials or user interaction, which is why CVSS rates this 9.8 (critical). A public proof-of-concept has been available since March 2020, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03, indicating confirmed in-the-wild exploitation; EPSS estimates an 86.4% probability of exploitation within 30 days. Any organization running Planning Analytics in the affected version range should treat reachable TM1 server instances, especially internet-exposed ones, as at risk.
What to do: Upgrade IBM Planning Analytics to a fixed release beyond version 2.0.8 following IBM's security advisory, as required by the CISA KEV catalog. Until patched, restrict network access to TM1 services (do not expose admin/API ports to the internet) and review logs for unauthenticated admin logins or unexpected configuration changes. Prioritize patching internet-exposed instances given the critical CVSS score, high EPSS, and KEV listing.
| IBM Planning Analytics | 2.0.0 through 2.0.8 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
- Affected
- IBM Planning Analytics
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- ibm
- Products
- planning analytics
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.