Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2024-35143
Disclosure Date: August 04, 2024 (last updated September 12, 2024)
IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 292420.
0
Attacker Value
Unknown
CVE-2022-22314
Disclosure Date: September 06, 2022 (last updated October 08, 2023)
IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 217371.
0
Attacker Value
Unknown
CVE-2021-39040
Disclosure Date: April 22, 2022 (last updated February 23, 2025)
IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 214025.
0
Attacker Value
Unknown
CVE-2022-22392
Disclosure Date: April 22, 2022 (last updated February 23, 2025)
IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066.
0