CVE-2024-35143: IBM Planning Analytics Local
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 292420.
Affected products
- IBM Planning Analytics Local: from 2.0, before 2.0.97 (fixed in 2.0.97); from 2.1.0, before 2.1.4 (fixed in 2.1.4)
- IBM Planning Analytics Workspace: from 2.0, before 2.0.97 (fixed in 2.0.97); from 2.1, before 2.1.4 (fixed in 2.1.4)
Published 2024-08-04. Last modified 2026-06-17.