PT-2022-1587 · Ibm · Ibm Planning Analytics Workspace+1
Published
2022-01-12
·
Updated
2022-02-11
·
CVE-2021-38892
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM Planning Analytics versions 2.0
IBM Planning Analytics Workspace versions 2.0
Description
The issue is related to incorrect restriction of a directory path with limited access. Exploitation may allow a remote attacker to execute arbitrary code. A remote threat actor can access a valid endpoint without prior authentication, allowing them to read and write files to the system, potentially leading to path traversal and remote code execution, depending on file system permissions.
Recommendations
For IBM Planning Analytics version 2.0, consider restricting access to the DQM API to prevent unauthenticated sessions.
For IBM Planning Analytics Workspace version 2.0, restrict access to the DQM API to minimize the risk of exploitation.
As a temporary workaround, consider disabling the
DQM API until a patch is available.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Planning Analytics
Ibm Planning Analytics Workspace