
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36357 is an absolute path traversal vulnerability in IBM Planning Analytics Local that allows a remote authenticated user to traverse directories and access arbitrary files on the affected system. It affects IBM Planning Analytics Local and Planning Analytics Workspace versions 2.1.0 through 2.1.14. The vulnerability was published on November 17, 2025, and received a CVSS v3.1 base score of 8.0 (High) (IBM Advisory, NVD). Note: Microsoft's Security Update Guide also references this CVE identifier in the context of an AMD processor vulnerability addressed via Windows updates (AMD-SB-7029), but the primary software vulnerability documented by IBM is the Planning Analytics path traversal issue (MSRC).
The vulnerability is classified as CWE-36 (Absolute Path Traversal), where insufficient validation of user-supplied URL input allows absolute path sequences to bypass directory restrictions. An authenticated remote attacker can send a specially crafted HTTP request containing absolute path sequences to the application, causing the server to resolve and access files outside the intended directory scope. Exploitation requires low privileges and user interaction (CVSS PR:L, UI:R), and operates over the network without requiring local access. No public technical write-ups or proof-of-concept code have been identified at this time (IBM Advisory, NVD).
Successful exploitation allows an authenticated attacker to view, read, or write arbitrary files on the affected system, resulting in high confidentiality, integrity, and availability impact. An attacker could exfiltrate sensitive configuration files, credentials, or business data stored on the server, and could also overwrite or corrupt critical files to disrupt service availability. The ability to write arbitrary files may further enable privilege escalation or persistence on the compromised host (IBM Advisory, NVD).
There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.059%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (IBM Advisory, ENISA EUVD).
/etc/passwd or C:\Windows\System32\config\SAM) in the URL parameter to bypass directory restrictions./etc/, C:\, \\) in URL parameters; unexpected outbound connections from the Planning Analytics server to external hosts./etc/passwd, configuration files) updated unexpectedly.IBM has released a fix in IBM Planning Analytics Local and Planning Analytics Workspace version 2.1.15, which users should upgrade to immediately (IBM Advisory). As interim mitigations, organizations should implement strict input validation for URL requests at the web application firewall (WAF) level, restrict and monitor user privileges within the application, and limit network access to the Planning Analytics application to trusted users and IP ranges. Additionally, Microsoft has released Windows updates that address the related AMD processor vulnerability (AMD-SB-7029) referenced under the same CVE identifier, and applying the latest Windows security updates is recommended (MSRC).
CVE-2025-36357 was noted in the context of Microsoft's July 2025 Patch Tuesday coverage, where it was referenced in relation to AMD processor mitigations, generating broad media coverage of the overall patch release (BleepingComputer, Sophos News). The IBM-specific path traversal aspect received standard vulnerability database coverage without notable researcher commentary or significant social media discussion. CISA included it in a weekly vulnerability summary bulletin for the week of November 17, 2025 (CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."