CVE-2024-35143
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD
Description
IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 292420.
Affected (4)
Products: Ibm: Planning Analytics Workspace, Planning Analytics Local
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0 to 2.0.97 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0 to 2.0.97 |
References (2)
Source: psirt@us.ibm.com
Broken LinkVDB Entry
Timeline
No history available yet.