CVE-2021-38873
Published Nov 23, 2021
·Updated
IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 208396.
Affected Software
1 affected component
IBM Planning Analytics=2.0
Remediation
Patch Available
Event History
Nov 23, 2021
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Nov 24, 2021
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-38873.
2
What is the severity of CVE-2021-38873?
The severity of CVE-2021-38873 is critical.
3
How does IBM Planning Analytics version 2.0 become vulnerable to CSV Injection?
IBM Planning Analytics version 2.0 becomes vulnerable to CSV Injection due to improper validation of csv file contents.
4
What is CSV Injection?
CSV Injection is a technique where an attacker can manipulate the content of a CSV file to execute arbitrary commands on the system.
5
Is there a fix available for CVE-2021-38873 in IBM Planning Analytics version 2.0?
Yes, IBM has provided a fix for this vulnerability. Please refer to the IBM support page for more information on how to apply the fix.