Improper Authentication in Planning Analytics Local - CVE-2021-38892

 

Improper Authentication in Planning Analytics Local - CVE-2021-38892

Published: January 12, 2022


Vulnerability identifier: #VU59560
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38892
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to DQM API allows submitting of all control requests in unauthenticated sessions. A remote attacker can access a valid PA endpoint to read and write files to the IBM Planning Analytics system.

Successful exploitation of the vulnerability may result in complete compromise of the system.


Affected software

Planning Analytics Local

How to mitigate CVE-2021-38892

Install updates from vendor's website.

Planning Analytics Local - update to 2.0.9.11

External References

Related Security Bulletins