CVE-2020-4669
MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.94%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 184600.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 1.94% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- ibm/planning analytics cloud · ibm/planning analytics local
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/186400VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6436821Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/186400VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6436821Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.