ZeroHour

CVE-2019-4716

KEV PoC ×2moderate

Unauthenticated RCE in IBM Planning Analytics 2.0

CISA: IBM Planning Analytics Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
86%p100
Published
()
KEV added
AI analysis

IBM Planning Analytics 2.0.0 through 2.0.8 contains a configuration overwrite flaw that allows an unauthenticated remote attacker to log in as the 'admin' account. Once authenticated as admin, the attacker can execute arbitrary code via TM1 scripting, running as root on Linux servers or as SYSTEM on Windows. Exploitation requires only network access to the vulnerable service, with no credentials or user interaction, which is why CVSS rates this 9.8 (critical). A public proof-of-concept has been available since March 2020, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03, indicating confirmed in-the-wild exploitation; EPSS estimates an 86.4% probability of exploitation within 30 days. Any organization running Planning Analytics in the affected version range should treat reachable TM1 server instances, especially internet-exposed ones, as at risk.

What to do: Upgrade IBM Planning Analytics to a fixed release beyond version 2.0.8 following IBM's security advisory, as required by the CISA KEV catalog. Until patched, restrict network access to TM1 services (do not expose admin/API ports to the internet) and review logs for unauthenticated admin logins or unexpected configuration changes. Prioritize patching internet-exposed instances given the critical CVSS score, high EPSS, and KEV listing.

Affected
IBM Planning Analytics2.0.0 through 2.0.8
Estimated exposure
moderateroughly 1,000–10,000 enterprise deployments (exact install counts unknown) — No public install-count data exists for this enterprise product, so the estimate reflects typical adoption of IBM planning/BI software by mid-size and large organizations, with only a subset of TM1 server instances exposed to the internet.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.

CISA Known Exploited Vulnerability
Affected
IBM Planning Analytics
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
ibm
Products
planning analytics
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.