漏洞描述
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
seclists.orghttp://seclists.org/fulldisclosure/2020/Mar/44↗www.ibm.comhttps://www.ibm.com/support/pages/node/1127781↗packetstormsecurity.comhttp://packetstormsecurity.com/files/156953/IBM-Cognos-TM1-IBM-Planning-Analytics-Server-Configuration-Overwrite-Code-Execution.html↗exchange.xforce.ibmcloud.comhttps://exchange.xforce.ibmcloud.com/vulnerabilities/172094↗