Ibm Planning Analytics vulnerabilities

32 known vulnerabilities affecting ibm/planning_analytics.

Total CVEs
32
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH8MEDIUM22

Vulnerabilities

Page 2 of 2
CVE-2020-4653MEDIUMCVSS 6.1v2.02020-08-19
CVE-2020-4653 [MEDIUM] CWE-601 CVE-2020-4653: IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the
cvelistv5nvd
CVE-2020-4648MEDIUMCVSS 6.5v2.02020-08-19
CVE-2020-4648 [MEDIUM] CVE-2020-4648: A vulnerability exsists in IBM Planning Analytics 2.0 whereby avatars in Planning Analytics Workspac A vulnerability exsists in IBM Planning Analytics 2.0 whereby avatars in Planning Analytics Workspace could be modified by other users without authorization to do so. IBM X-Force ID: 186019.
cvelistv5nvd
CVE-2020-4645MEDIUMCVSS 5.4v2.0.0v2.0.9.12020-07-29
CVE-2020-4645 [MEDIUM] CWE-79 CVE-2020-4645: IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulne IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 185717.
cvelistv5nvd
CVE-2020-4644MEDIUMCVSS 5.4v2.0.0v2.0.9.12020-07-29
CVE-2020-4644 [MEDIUM] CWE-1021 CVE-2020-4644: IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the click IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 185716.
cvelistv5nvd
CVE-2020-4527MEDIUMCVSS 5.9v2.02020-07-20
CVE-2020-4527 [MEDIUM] CWE-384 CVE-2020-4527: IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the Secure flag for the session cookie in TLS mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM X-Force ID: 182631.
cvelistv5nvd
CVE-2020-4361MEDIUMCVSS 4.3v2.02020-07-20
CVE-2020-4361 [MEDIUM] CWE-200 CVE-2020-4361: IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by disclosi IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by disclosing private IP addresses in HTTP responses. IBM X-Force ID: 178766.
cvelistv5nvd
CVE-2019-4613HIGHCVSS 8.8v2.02020-02-05
CVE-2019-4613 [HIGH] CWE-352 CVE-2019-4613: IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 168524.
cvelistv5nvd
CVE-2019-4716CRITICALCVSS 9.8KEVPoC≥ 2.0, ≤ 2.0.8v2.0.0+1 more2019-12-18
CVE-2019-4716 [CRITICAL] CWE-94 CVE-2019-4716: IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
cvelistv5nvd
CVE-2019-4612HIGHCVSS 8.8v2.0v22019-12-09
CVE-2019-4612 [HIGH] CWE-434 CVE-2019-4612: IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attacker IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 168523.
cvelistv5nvd
CVE-2019-4611MEDIUMCVSS 5.4v2.0v22019-12-09
CVE-2019-4611 [MEDIUM] CWE-79 CVE-2019-4611: IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168519.
cvelistv5nvd
CVE-2019-4134MEDIUMCVSS 6.1v2.02019-07-02
CVE-2019-4134 [MEDIUM] CWE-79 CVE-2019-4134: IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158281.
nvd
CVE-2018-1933MEDIUMCVSS 5.4≥ 2.0, ≤ 2.0.6v2.0.3+6 more2019-05-01
CVE-2018-1933 [MEDIUM] CWE-79 CVE-2018-1933: IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability a IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153177.
cvelistv5nvd
Ibm Planning Analytics vulnerabilities | cvebase