Ibm Planning Analytics Workspace vulnerabilities
8 known vulnerabilities affecting ibm/planning_analytics_workspace.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-36357HIGHCVSS 8.0≥ 2.1.0, < 2.1.152025-11-17
CVE-2025-36357 [HIGH] CWE-36 CVE-2025-36357: IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to travers
IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences to view, read, or write arbitrary files on the system.
nvd
CVE-2025-36299MEDIUMCVSS 4.3≥ 2.1.0, < 2.1.152025-11-17
CVE-2025-36299 [MEDIUM] CWE-540 CVE-2025-36299: IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could
IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system.
nvd
CVE-2024-35143CRITICALCVSS 9.1≥ 2.0, < 2.0.97≥ 2.1, < 2.1.42024-08-04
CVE-2024-35143 [MEDIUM] CWE-306 CVE-2024-35143: IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented
IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 292420.
nvd
CVE-2022-22314LOWCVSS 3.3v2.02022-09-08
CVE-2022-22314 [LOW] CVE-2022-22314: IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another
IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 217371.
cvelistv5nvd
CVE-2022-22392HIGHCVSS 7.8v2.02022-04-25
CVE-2022-22392 [HIGH] CWE-434 CVE-2022-22392: IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which,
IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066.
cvelistv5nvd
CVE-2021-39040HIGHCVSS 8.0v2.02022-04-25
CVE-2021-39040 [HIGH] CWE-434 CVE-2021-39040: IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating
IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 214025.
cvelistv5nvd
CVE-2022-22308HIGHCVSS 7.8v2.02022-02-21
CVE-2022-22308 [HIGH] CWE-829 CVE-2022-22308: IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be
IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into including remote files with malicious code. IBM X-Force ID: 216891.
cvelistv5nvd
CVE-2020-4649MEDIUMCVSS 4.3v572020-11-03
CVE-2020-4649 [MEDIUM] CWE-200 CVE-2020-4649: IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to no
IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions. IBM X-Force ID: 186022.
cvelistv5nvd