4.9
CVE-2025-36262
- EPSS 0.06%
- Veröffentlicht 30.09.2025 20:15:37
- Zuletzt bearbeitet 03.10.2025 17:52:19
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Planning Analytics Local information disclosure
IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Planning Analytics Local Version >= 2.0.0 <= 2.0.106
Ibm ≫ Planning Analytics Local Version >= 2.1.0 <= 2.1.13
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.188 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-1286 Improper Validation of Syntactic Correctness of Input
The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.