CVE-2022-22308
Description
IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into including remote files with malicious code. IBM X-Force ID: 216891.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Planning Analytics 2.0 is vulnerable to Remote File Include (RFI) via crafted user input, allowing execution of malicious remote code.
Vulnerability
IBM Planning Analytics Workspace 2.0 is vulnerable to a Remote File Include (RFI) attack. The application accepts user input that is passed into file include commands without proper sanitization, allowing an attacker to trick the web application into including remote files containing malicious code. Affected versions are prior to 2.0.73. [1]
Exploitation
An attacker does not require authentication and can exploit the vulnerability remotely over the network. By crafting a malicious request containing a specially crafted input (e.g., a URL pointing to an attacker-controlled server with a malicious file), the attacker can cause the application to include and execute that remote file. No user interaction is required. [1]
Impact
Successful exploitation allows the attacker to execute arbitrary code on the server hosting IBM Planning Analytics Workspace. This can lead to full compromise of the application and underlying system, including unauthorized access to sensitive data, modification of files, and potential lateral movement within the network. The CIA impact is high. [1]
Mitigation
The vulnerability is fixed in IBM Planning Analytics Workspace version 2.0.73, released as part of a security bulletin. Users must upgrade to version 2.0.73 or later to mitigate the RFI risk. No workaround is documented; upgrading is the recommended action. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: = 2.0
- Range: 2.0
- IBM/Planning Analytics Workspacev5Range: 2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/216891mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/6557106mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.