| Title | IBM Planning Analytics - Authentication Bypass & Remote Code Execution Version Detection |
|---|---|
| Author | 0x_Akoko |
| Severity | Critical |
| Impact | Attackers can gain admin access and execute arbitrary code with SYSTEM privileges, leading to full system compromise. |
| Remediation | Update to the latest version or 2.0.9 or apply the security patches provided by IBM. |
| CVSS Score | 9.8 |
| EPSS Score | 0.91546 |
| CVE ID | CVE-2019-4716 |
| CWE ID | CWE-94 |
| Shodan Query | title:"Arc for TM1" |
| Tags | cve cve2019 ibm planning_analytics passive kev vkev |
IBM Planning Analytics versions 2.0.0 through 2.0.8 are vulnerable to a configuration overwrite that allows an unauthenticated user to login as “admin”, and then execute code as root or SYSTEM via TM1 scripting.
GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-4716.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-4716.pcap
N/AN/A