LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-4716: IBM Planning Analytics Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-4716 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.

CVE-2019-4716 is a remote code execution vulnerability in IBM Planning Analytics. It stems from a configuration overwrite that lets an unauthenticated attacker gain admin access and then run code with root or SYSTEM privileges through TM1 scripting. For IT and security teams, this matters because successful abuse can give full control of the host running the analytics platform, putting planning data, connected systems, and credentials at risk.

CISA lists the required action as applying updates per vendor instructions. Confirm exact affected builds, fixed versions, and deployment notes directly against the IBM advisory before acting.

How it works

The weakness is classified as CWE-94 (improper control of code generation, commonly called code injection). In this case the product allows an unauthenticated user to overwrite configuration in a way that grants an “admin” login. Once that privileged session is obtained, the attacker can invoke TM1 scripting to execute arbitrary code as root on Linux or SYSTEM on Windows.

At a high level the abuse path is: reach the exposed Planning Analytics interface, perform the configuration overwrite to elevate to admin, then supply malicious TM1 script content that the service executes with the highest local privileges. No further authentication is required after the initial overwrite. Specific request formats, endpoints, or payload construction are not detailed here; treat any public proof-of-concept material with caution and validate behavior only in a lab against the vendor’s description.

Am I affected? How to find it in your systems

IBM Planning Analytics is typically deployed as an on-premises or private-cloud analytics and planning server, often integrated with TM1 engines and used by finance and operations teams. It may appear as a Windows or Linux service, sometimes fronted by a web tier or application server.

Inventory steps:

Telemetry that may indicate exploitation includes unexpected configuration file changes, sudden creation of admin-level sessions from untrusted source IPs, or TM1 script execution events outside normal business processes. Correlate web or application logs for unauthenticated access patterns that precede privileged script runs. Absence of such logs does not prove safety; the product may not record every step of the attack by default.

How to remediate

Patch first. Obtain and apply the updates IBM released for this vulnerability, following the exact installation and restart procedures in the vendor advisory. CISA’s required action is simply to apply those vendor updates.

After patching:

Re-scan or re-inventory after remediation to confirm no unpatched instances remain.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures lower risk but do not eliminate the vulnerability; schedule the official patch as soon as possible.

If your data may have been exposed

Actively exploited remote-code-execution flaws frequently lead to data theft, lateral movement, or ransomware deployment, although ransomware use specifically tied to CVE-2019-4716 is not documented. If you suspect compromise, isolate the host, preserve volatile evidence, and begin incident-response procedures. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIBM · Planning Analytics
WeaknessCWE-94
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities