CVE-2021-29852
- EPSS 0.14%
- Published 01.09.2021 17:15:07
- Last modified 21.11.2024 06:01:55
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted...
CVE-2021-29851
- EPSS 0.09%
- Published 01.09.2021 17:15:07
- Last modified 21.11.2024 06:01:55
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 205527.
CVE-2021-20580
- EPSS 0.09%
- Published 29.06.2021 16:15:08
- Last modified 21.11.2024 05:46:48
IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 198241.
CVE-2021-20477
- EPSS 0.21%
- Published 29.06.2021 16:15:08
- Last modified 21.11.2024 05:46:38
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted...
CVE-2020-4562
- EPSS 0.19%
- Published 26.04.2021 17:15:07
- Last modified 21.11.2024 05:32:54
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window communication with unrestricted target origin via documentation frames.
CVE-2020-4882
- EPSS 0.12%
- Published 22.03.2021 17:15:14
- Last modified 21.11.2024 05:33:21
IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This could enable attackers to make arbitrary requests to the internal network or to the local file system. ...
CVE-2020-4953
- EPSS 0.1%
- Published 23.02.2021 16:15:12
- Last modified 21.11.2024 05:33:28
IBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's internal structure by exposing sensitive information in HTTP repsonses. IBM X-Force ID: 192029.
CVE-2020-4881
- EPSS 0.22%
- Published 19.01.2021 16:15:13
- Last modified 21.11.2024 05:33:21
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/TLS communication. By sending a specially-crafted request, an attacker could exploit this vulnerabili...
CVE-2020-4873
- EPSS 0.14%
- Published 19.01.2021 16:15:13
- Last modified 21.11.2024 05:33:21
IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.
CVE-2020-4871
- EPSS 0.05%
- Published 19.01.2021 16:15:12
- Last modified 21.11.2024 05:33:20
IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834.