PT-2022-10859 · Ibm · Ibm Planning Analytics Workspace
Published
2022-04-25
·
Updated
2022-05-03
·
CVE-2021-39040
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Planning Analytics Workspace version 2.0
Description
The issue allows malicious file upload by not validating the file types or sizes. Attackers can exploit this weakness to upload malicious executable files into the system, which can then be sent to victims for further attacks.
Recommendations
For IBM Planning Analytics Workspace version 2.0, consider implementing file type and size validation to prevent malicious file uploads until a patch is available. As a temporary workaround, restrict access to file upload functionality to minimize the risk of exploitation.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Planning Analytics Workspace