Aller au contenu

Fiche vulnérabilité

CVE-2024-25034 : faille élevée ibm planning analytics (CVSS 8.8)

Description

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in the File Manager T1 process. Attackers can make use of this weakness and upload malicious executable files into the system that can be sent to victims for performing further attacks.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
24 janv. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • ibm planning analytics

Références

Rechercher une autre vulnérabilité dans la base CVE