Skip to content
COOEY

EXPOSURES › CVE-2019-4716

CVE-2019-4716

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-4716 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

IBM Planning Analytics allowed unauthenticated remote code execution via configuration overwrite, enabling root-level access.

An unauthenticated user could overwrite a configuration to log in as 'admin' and execute code as root or SYSTEM through TM1 scripting. This is a critical failure for DIB organizations because it represents a severe, avoidable exposure where an attacker gains full system control without needing credentials, directly impacting compliance by demonstrating a lack of basic access controls and patch management. Organizations must ensure all software, especially business intelligence and analytics tools, are rigorously patched and monitored for known vulnerabilities.

Shame score — A configuration overwrite flaw allowing unauthenticated remote code execution as root is a severe, avoidable failure that demonstrates a lack of fundamental security hygiene and exposes the system to total compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Critical vulnerability allowing unauthenticated admin access and code execution as root
cooey ↗ severe-fallout -0.80
Critical vulnerability allowing unauthenticated admin access and code execution as root
"IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as 'admin', and then execute code as root or SYSTEM via TM1 scripting."
AFFECTED FEDRAMP PRODUCTS · 5
PRODUCTSTATUS
IBM Cloud for Government
IBM
Authorized
IBM Federal HR Cloud
IBM
Authorized
IBM Maximo and TRIRIGA on Cloud for U.S. Federal
IBM
Authorized
MaaS360 Enterprise Mobility Management
IBM
Authorized
SmartCloud for Government
IBM
Authorized