Vulnerability record · CVE-2019-4716 · published 18 December 2019
CVE-2019-4716: IBM Planning Analytics configuration overwrite leads to admin login and code execution
Ibm · Planning Analytics
IBM Planning Analytics 2.0.0 through 2.0.8 allows a configuration overwrite that lets an unauthenticated attacker log in as "admin" and then execute code as root or SYSTEM through TM1 scripting. The flaw is a code injection issue rated critical, and because it grants administrative access and OS-level execution, it is a severe risk to any exposed deployment.
Description
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable code execution as root/SYSTEM, listed in CISA KEV with very high EPSS and public exploits.
What it is
IBM Planning Analytics 2.0.0 through 2.0.8 allows a configuration overwrite that lets an unauthenticated attacker log in as "admin" and then execute code as root or SYSTEM through TM1 scripting. The flaw is a code injection issue rated critical, and because it grants administrative access and OS-level execution, it is a severe risk to any exposed deployment.
Impact
An attacker gains administrative control of the Planning Analytics server and can execute arbitrary code with root or SYSTEM privileges, leading to full host compromise.
Attack surface
The vulnerability is network-reachable with no authentication and no user interaction required, per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet- or network-exposed Planning Analytics instance in the affected range is directly reachable.
Exploitation
CVE-2019-4716 is listed in CISA KEV (added 2021-11-03) and has a high EPSS probability of about 0.86 (99.7th percentile), and public exploit references exist, indicating active exploitation in the wild.
What to do
- Apply the vendor patch from IBM support page node/1127781 and upgrade Planning Analytics beyond 2.0.8.
- Restrict network access to the Planning Analytics/TM1 server so it is not exposed to untrusted networks.
- Change default or weak administrative credentials and enforce strong authentication.
- Monitor for unauthorized configuration changes to TM1/Planning Analytics server settings.
- Review and limit TM1 scripting privileges to reduce post-exploitation impact.
Detection
- Audit Planning Analytics/TM1 logs for unexpected admin logins or configuration overwrite events.
- Alert on creation or modification of TM1 scripts or processes that spawn OS commands.
- Monitor for child processes from the Planning Analytics service running as root or SYSTEM.
- Watch for anomalous network connections to the Planning Analytics server from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-4716 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "IBM Planning Analytics Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/156953/IBM-Cognos-TM1-IBM-Planning-Analytics-Server-Configuration-Overwrite-Code-Ex | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2020/Mar/44 | ExploitMailing ListThird Party Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/172094 | VDB EntryVendor Advisory |
| https://www.ibm.com/support/pages/node/1127781 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/156953/IBM-Cognos-TM1-IBM-Planning-Analytics-Server-Configuration-Overwrite-Code-Ex | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2020/Mar/44 | ExploitMailing ListThird Party Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/172094 | VDB EntryVendor Advisory |
| https://www.ibm.com/support/pages/node/1127781 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-4716 | US Government Resource |
Track CVE-2019-4716 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-4716), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.