4.9

CVE-2025-36262

IBM Planning Analytics Local information disclosure

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 

could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmPlanning Analytics Local Version >= 2.0.0 <= 2.0.106
IbmPlanning Analytics Local Version >= 2.1.0 <= 2.1.13
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.188
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-1286 Improper Validation of Syntactic Correctness of Input

The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.