CVE-2024-25034
CVSS 3.1 Score 8 of 10 (high)
Details
Published Jan 24, 2025
CWE ID 434
Summary
CVE-2024-25034 is a vulnerability affecting IBM Planning Analytics 2.0 and 2.1. In this issue, the File Manager T1 process fails to validate the type of uploaded files, creating an opportunity for attackers to upload malicious executable files. By exploiting this weakness, attackers can gain unauthorized access to the system, potentially launching further attacks on unsuspecting victims. This vulnerability underscores the importance of rigorous file validation checks in maintaining the security of business-critical applications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- IBM Corporation