CVE-2019-4716

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:planning_analytics:*:*:*:*:*:*:*:*

History

22 Oct 2025, 00:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-4716 -

21 Oct 2025, 20:17

Type Values Removed Values Added
References
  • {'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-4716', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}

21 Oct 2025, 19:17

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-4716 -

Information

Published : 2019-12-18 17:16

Updated : 2025-10-22 00:16


NVD link : CVE-2019-4716

Mitre link : CVE-2019-4716

CVE.ORG link : CVE-2019-4716


JSON object : View

Products Affected

ibm

  • planning_analytics
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')