Remote File Include Vulnerability in IBM Planning Analytics
CVE-2022-22308

7.1HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
21 February 2022

Summary

IBM Planning Analytics 2.0 is susceptible to a Remote File Include (RFI) vulnerability, allowing attackers to exploit user input within file include commands. This could enable the web application to inadvertently include and execute remote files containing malicious code, potentially compromising the security of the entire system. Users are advised to review their configurations and implement security best practices to mitigate the risks associated with this vulnerability.

Affected Version(s)

Planning Analytics 2.0

Planning Analytics Workspace 2.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.