← Back to CVE List
Vulnerability Intelligence Report

CVE-2022-22308

IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into including remote files with malicious code. IBM X-Force ID: 216891.

No Active Exploit Signals
CVSS Base Score
7.1
HIGH
Exploitability:1.7
Impact Score:5.5
Temporal Score:6.2
EPSS Probability:0.74%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
IBM Planning Analytics 2.0 (affected)
IBM Planning Analytics Workspace 2.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.736%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityIBM Corporation · Vendor · USA
Reserved2022-01-03T00:00:00
Published2022-02-21T18:10:10
Patch Date2022-02-18
Last Updated2024-09-16T18:13:10

LINK COPIED TO CLIPBOARD