CVE-2024-25034

CVSS 3.1 Score 8 of 10 (high)

Details

Published Jan 24, 2025
CWE ID 434

Summary

CVE-2024-25034 is a vulnerability affecting IBM Planning Analytics 2.0 and 2.1. In this issue, the File Manager T1 process fails to validate the type of uploaded files, creating an opportunity for attackers to upload malicious executable files. By exploiting this weakness, attackers can gain unauthorized access to the system, potentially launching further attacks on unsuspecting victims. This vulnerability underscores the importance of rigorous file validation checks in maintaining the security of business-critical applications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share