Malicious File Upload Vulnerability in IBM Planning Analytics
CVE-2024-25034
8HIGH
Summary
IBM Planning Analytics versions 2.0 and 2.1 are susceptible to a file upload vulnerability due to a lack of validation for file types during the File Manager T1 process. This security flaw enables attackers to upload malicious executable files, which can subsequently be sent to unsuspecting victims for executing further exploits, potentially compromising system integrity and user data.
Affected Version(s)
Planning Analytics Local 2.0, 2.1
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved