PT-2022-15406 · Ibm · Ibm Planning Analytics Local
Published
2022-04-25
·
Updated
2022-05-05
·
CVE-2022-22392
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Planning Analytics Local version 2.0
Description
The issue allows an attacker to upload arbitrary executable files, which could result in code execution when executed by an unsuspecting victim.
Recommendations
For IBM Planning Analytics Local version 2.0, consider restricting access to file upload functionality to minimize the risk of exploitation until a patch is available.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Planning Analytics Local