Unauthorized Access to MongoDB Database via Remote Port
CVE-2024-35143
9.1CRITICAL
What is CVE-2024-35143?
IBM Planning Analytics Local versions 2.0 and 2.1 are vulnerable due to their connection configuration with MongoDB, a popular document-oriented database system. The MongoDB server is set to listen on a remote port and is configured to allow connections without requiring password authentication. This misconfiguration allows a remote attacker to exploit this weakness and gain unauthorized access to the database, potentially leading to the exposure of sensitive information and data integrity issues. Security measures should be taken to secure MongoDB instances and properly authenticate all connections to mitigate these risks.
Affected Version(s)
Planning Analytics Local 2.0, 2.1