Unauthorized Access to MongoDB Database via Remote Port
CVE-2024-35143
9.1CRITICAL
Summary
IBM Planning Analytics Local versions 2.0 and 2.1 are vulnerable due to their connection configuration with MongoDB, a popular document-oriented database system. The MongoDB server is set to listen on a remote port and is configured to allow connections without requiring password authentication. This misconfiguration allows a remote attacker to exploit this weakness and gain unauthorized access to the database, potentially leading to the exposure of sensitive information and data integrity issues. Security measures should be taken to secure MongoDB instances and properly authenticate all connections to mitigate these risks.
Affected Version(s)
Planning Analytics Local 2.0, 2.1
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved