CVE-2025-36357
vulnerability analysis and mitigation

Overview

CVE-2025-36357 is an absolute path traversal vulnerability in IBM Planning Analytics Local that allows a remote authenticated user to traverse directories and access arbitrary files on the affected system. It affects IBM Planning Analytics Local and Planning Analytics Workspace versions 2.1.0 through 2.1.14. The vulnerability was published on November 17, 2025, and received a CVSS v3.1 base score of 8.0 (High) (IBM Advisory, NVD). Note: Microsoft's Security Update Guide also references this CVE identifier in the context of an AMD processor vulnerability addressed via Windows updates (AMD-SB-7029), but the primary software vulnerability documented by IBM is the Planning Analytics path traversal issue (MSRC).

Technical details

The vulnerability is classified as CWE-36 (Absolute Path Traversal), where insufficient validation of user-supplied URL input allows absolute path sequences to bypass directory restrictions. An authenticated remote attacker can send a specially crafted HTTP request containing absolute path sequences to the application, causing the server to resolve and access files outside the intended directory scope. Exploitation requires low privileges and user interaction (CVSS PR:L, UI:R), and operates over the network without requiring local access. No public technical write-ups or proof-of-concept code have been identified at this time (IBM Advisory, NVD).

Impact

Successful exploitation allows an authenticated attacker to view, read, or write arbitrary files on the affected system, resulting in high confidentiality, integrity, and availability impact. An attacker could exfiltrate sensitive configuration files, credentials, or business data stored on the server, and could also overwrite or corrupt critical files to disrupt service availability. The ability to write arbitrary files may further enable privilege escalation or persistence on the compromised host (IBM Advisory, NVD).

Exploitability

There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.059%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (IBM Advisory, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify internet-facing IBM Planning Analytics Local or Planning Analytics Workspace instances running versions 2.1.0 through 2.1.14 using network scanning or application fingerprinting tools.
  2. Authentication: Obtain valid low-privileged credentials for the Planning Analytics application through phishing, credential stuffing, or other means, as exploitation requires an authenticated session.
  3. Craft malicious request: Construct an HTTP request targeting a vulnerable endpoint in the application, embedding absolute path sequences (e.g., /etc/passwd or C:\Windows\System32\config\SAM) in the URL parameter to bypass directory restrictions.
  4. Exfiltrate or modify files: Submit the crafted request to read sensitive files (configuration files, credentials, application data) or write malicious content to arbitrary locations on the server, potentially enabling further compromise (IBM Advisory, NVD).

Indicators of compromise

  • Network: Unusual HTTP requests to Planning Analytics endpoints containing absolute path sequences (e.g., /etc/, C:\, \\) in URL parameters; unexpected outbound connections from the Planning Analytics server to external hosts.
  • Logs: Application access logs showing requests with absolute path patterns in URL query strings; repeated 200 OK responses to requests targeting system file paths; authentication events from unfamiliar IP addresses.
  • File System: Unexpected new or modified files in sensitive directories (e.g., web root, system directories) that may indicate write exploitation; access timestamps on sensitive system files (e.g., /etc/passwd, configuration files) updated unexpectedly.
  • Process: Unusual child processes spawned by the Planning Analytics application service account accessing files outside the application directory.

Mitigation and workarounds

IBM has released a fix in IBM Planning Analytics Local and Planning Analytics Workspace version 2.1.15, which users should upgrade to immediately (IBM Advisory). As interim mitigations, organizations should implement strict input validation for URL requests at the web application firewall (WAF) level, restrict and monitor user privileges within the application, and limit network access to the Planning Analytics application to trusted users and IP ranges. Additionally, Microsoft has released Windows updates that address the related AMD processor vulnerability (AMD-SB-7029) referenced under the same CVE identifier, and applying the latest Windows security updates is recommended (MSRC).

Community reactions

CVE-2025-36357 was noted in the context of Microsoft's July 2025 Patch Tuesday coverage, where it was referenced in relation to AMD processor mitigations, generating broad media coverage of the overall patch release (BleepingComputer, Sophos News). The IBM-specific path traversal aspect received standard vulnerability database coverage without notable researcher commentary or significant social media discussion. CISA included it in a weekly vulnerability summary bulletin for the week of November 17, 2025 (CISA Bulletin).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management