CVE-2024-25034

HIGH

IBM Planning Analytics <2.2 - Code Injection

Title source: llm
STIX 2.1

Description

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in the File Manager T1 process. Attackers can make use of this weakness and upload malicious executable files into the system that can be sent to victims for performing further attacks.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7168387

Scores

CVSS v3 8.0
EPSS 0.0015
EPSS Percentile 35.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
ibm/planning_analytics 2.0
ibm/planning_analytics 2.1
Published Jan 24, 2025
Tracked Since Feb 18, 2026