KEVIntel
9.8
CVSS
Critical

CVE-2019-4716

PUBLISHED

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and...

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
IBM
Product
Planning Analytics
Published
Dec 18, 2019
EPSS

Automate This Intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.

cisa nuclei_scanner metasploit

Weaknesses (CWE)

  • Improper Control of Generation of Code ('Code Injection')

CVSS Scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v3.0 10.0 Critical

CVSS:3.0/UI:N/AC:L/PR:N/I:H/S:C/AV:N/C:H/A:H/RC:C/RL:O/E:U

Exploitation Status

Exploited in the wild

Recorded 2021-11-03 00:00:00 UTC · CISA

Proof of concept available

Recorded 2025-04-28 15:02:27 UTC · Nuclei Templates

Known Exploited Vulnerability Sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA First 2021-11-03 00:00 UTC

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

CVE-2019-4716

nuclei · Created Unknown

ibm_tm1_unauth_rce

metasploit · Created Unknown

Metasploit module for CVE-2019-4716

Timeline

  • Detected by Nuclei

  • Detected by Metasploit

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • CVE Published to Public

  • CVE ID Reserved