CVE-2019-4716: IBM Planning Analytics Remote Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 86.4% chance of exploitation in the next 30 days.

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.

Affected products

  • IBM Planning Analytics: from 2.0, up to and including 2.0.8

Published 2019-12-18. Last modified 2026-06-17.