PT-2025-23425 · Ibm · Ibm Planning Analytics

Published

2025-05-30

·

Updated

2025-06-01

·

CVE-2025-33004

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Planning Analytics Local versions 2.0 through 2.1
Description The issue allows a privileged user to delete files from directories due to improper pathname restriction.
Recommendations For versions 2.0 and 2.1, restrict access to sensitive directories to prevent unauthorized file deletion. As a temporary workaround, consider implementing additional access controls to limit the ability of privileged users to delete files from critical directories.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-09703
CVE-2025-33004

Affected Products

Ibm Planning Analytics