HIGH🇵🇱 Wersja polska

CVE-2024-40693

CVSS 8.0v3.1pub. 2025-01-24upd. 2025-03-05

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
  • IBM Planning Analytics

    APP
    Ibm
    2.02.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-4716CRITICAL9.8⚠ KEVPL ✓same product

IBM Planning Analytics — nadpisanie konfiguracji umożliwia RCE jako root/SYSTEM

CVE-2024-25034HIGH8.0same product

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of ...

CVE-2023-42017HIGH8.0same product

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improp...

CVE-2022-22339HIGH7.3same product

IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticate...

CVE-2022-22308HIGH7.8same product

IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed int...