🔙 목록으로 돌아가기

CVE-2019-4716: IBM Planning Analytics - Authentication Bypass & Remote Code Execution Version Detection

TitleIBM Planning Analytics - Authentication Bypass & Remote Code Execution Version Detection
Author0x_Akoko
SeverityCritical
ImpactAttackers can gain admin access and execute arbitrary code with SYSTEM privileges, leading to full system compromise.
RemediationUpdate to the latest version or 2.0.9 or apply the security patches provided by IBM.
CVSS Score9.8
EPSS Score0.91546
CVE IDCVE-2019-4716
CWE IDCWE-94
Shodan Querytitle:"Arc for TM1"
Tags cve cve2019 ibm planning_analytics passive kev vkev

🔍 Vulnerability Description

IBM Planning Analytics versions 2.0.0 through 2.0.8 are vulnerable to a configuration overwrite that allows an unauthenticated user to login as “admin”, and then execute code as root or SYSTEM via TM1 scripting.

🌐 HTTP Request

GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-4716.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-4716.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A