Ibm

Planning Analytics Local

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 13.08.2026 19:34:02
  • Zuletzt bearbeitet 17.08.2026 17:37:48

IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

  • EPSS 0.22%
  • Veröffentlicht 30.07.2026 17:59:52
  • Zuletzt bearbeitet 12.08.2026 19:55:16

IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of sess...

  • EPSS 0.33%
  • Veröffentlicht 17.03.2026 21:50:24
  • Zuletzt bearbeitet 19.03.2026 14:42:50

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities due to lack of proper access controls.

  • EPSS 0.29%
  • Veröffentlicht 17.03.2026 21:50:21
  • Zuletzt bearbeitet 19.03.2026 14:43:11

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly cacheable resources.

  • EPSS 0.21%
  • Veröffentlicht 09.12.2025 22:16:10
  • Zuletzt bearbeitet 14.01.2026 20:40:25

IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could aid in further attacks against the system.

  • EPSS 0.82%
  • Veröffentlicht 17.11.2025 20:15:51
  • Zuletzt bearbeitet 07.10.2026 21:10:00

IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences to view, read, or write arbitra...

  • EPSS 0.21%
  • Veröffentlicht 17.11.2025 20:15:51
  • Zuletzt bearbeitet 07.10.2026 21:10:00

IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system.

  • EPSS 0.28%
  • Veröffentlicht 30.09.2025 20:15:37
  • Zuletzt bearbeitet 03.10.2025 17:52:19

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.

  • EPSS 0.18%
  • Veröffentlicht 30.09.2025 20:15:37
  • Zuletzt bearbeitet 03.10.2025 17:52:05

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali...

  • EPSS 0.21%
  • Veröffentlicht 01.06.2025 11:39:06
  • Zuletzt bearbeitet 09.06.2025 18:07:39

IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.