IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 208396.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/208396 | VDB Entry Vendor Advisory |
https://www.ibm.com/support/pages/node/6517470 | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ibm
Published: 2021-11-23T00:00:00
Updated: 2021-11-24T16:15:12
Reserved: 2021-08-16T00:00:00
Link: CVE-2021-38873
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-11-24T17:15:07.973
Modified: 2021-11-24T20:40:40.140
Link: CVE-2021-38873
JSON object: View
Redhat Information
No data.
CWE