Malicious File Upload Vulnerability in IBM Planning Analytics
CVE-2024-25034

8HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
24 January 2025

Summary

IBM Planning Analytics versions 2.0 and 2.1 are susceptible to a file upload vulnerability due to a lack of validation for file types during the File Manager T1 process. This security flaw enables attackers to upload malicious executable files, which can subsequently be sent to unsuspecting victims for executing further exploits, potentially compromising system integrity and user data.

Affected Version(s)

Planning Analytics Local 2.0, 2.1

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.