Show filters
38 Total Results
Displaying 1-10 of 38
Sort by:
Attacker Value
Unknown

CVE-2024-31908

Disclosure Date: May 31, 2024 (last updated January 13, 2025)
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289890.
Attacker Value
Unknown

CVE-2024-31907

Disclosure Date: May 31, 2024 (last updated January 13, 2025)
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289889.
Attacker Value
Unknown

CVE-2024-31889

Disclosure Date: May 31, 2024 (last updated January 13, 2025)
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 288136.
Attacker Value
Unknown

CVE-2023-42017

Disclosure Date: December 22, 2023 (last updated December 30, 2023)
IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious script, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 265567.
Attacker Value
Unknown

CVE-2023-28520

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250454.
Attacker Value
Unknown

CVE-2022-22314

Disclosure Date: September 06, 2022 (last updated October 08, 2023)
IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 217371.
Attacker Value
Unknown

CVE-2021-39047

Disclosure Date: June 22, 2022 (last updated November 29, 2024)
IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214349.
Attacker Value
Unknown

CVE-2021-39040

Disclosure Date: April 22, 2022 (last updated October 07, 2023)
IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 214025.
Attacker Value
Unknown

CVE-2022-22392

Disclosure Date: April 22, 2022 (last updated October 07, 2023)
IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066.
Attacker Value
Unknown

CVE-2022-22339

Disclosure Date: April 07, 2022 (last updated October 07, 2023)
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 219736.