EXPOSURES › CVE-2019-4716
CVE-2019-4716
HIGH ⌖ ON CISA KEV · EXPLOITEDIBM Planning Analytics allowed unauthenticated remote code execution via configuration overwrite, enabling root-level access.
An unauthenticated user could overwrite a configuration to log in as 'admin' and execute code as root or SYSTEM through TM1 scripting. This is a critical failure for DIB organizations because it represents a severe, avoidable exposure where an attacker gains full system control without needing credentials, directly impacting compliance by demonstrating a lack of basic access controls and patch management. Organizations must ensure all software, especially business intelligence and analytics tools, are rigorously patched and monitored for known vulnerabilities.
Shame score — A configuration overwrite flaw allowing unauthenticated remote code execution as root is a severe, avoidable failure that demonstrates a lack of fundamental security hygiene and exposes the system to total compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.
"IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as 'admin', and then execute code as root or SYSTEM via TM1 scripting."
| PRODUCT | STATUS |
|---|---|
| IBM Cloud for Government IBM |
Authorized |
| IBM Federal HR Cloud IBM |
Authorized |
| IBM Maximo and TRIRIGA on Cloud for U.S. Federal IBM |
Authorized |
| MaaS360 Enterprise Mobility Management IBM |
Authorized |
| SmartCloud for Government IBM |
Authorized |