CVE-2024-35143

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
04/08/2024
Last modified:
11/09/2024

Description

IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 292420.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:planning_analytics_workspace:*:*:*:*:*:*:*:* 2.0 (including) 2.0.97 (excluding)
cpe:2.3:a:ibm:planning_analytics_workspace:*:*:*:*:*:*:*:* 2.1 (including) 2.1.4 (excluding)
cpe:2.3:a:ibm:planning_analytics_local:*:*:*:*:*:*:*:* 2.0 (including) 2.0.97 (excluding)
cpe:2.3:a:ibm:planning_analytics_local:*:*:*:*:*:*:*:* 2.1.0 (including) 2.1.4 (excluding)