Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-31908
Disclosure Date: May 31, 2024 (last updated January 13, 2025)
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289890.
0
Attacker Value
Unknown
CVE-2024-31907
Disclosure Date: May 31, 2024 (last updated January 13, 2025)
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289889.
0
Attacker Value
Unknown
CVE-2024-31889
Disclosure Date: May 31, 2024 (last updated January 13, 2025)
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 288136.
0
Attacker Value
Unknown
CVE-2023-28520
Disclosure Date: May 12, 2023 (last updated October 08, 2023)
IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250454.
0
Attacker Value
Unknown
CVE-2021-29739
Disclosure Date: August 09, 2021 (last updated February 23, 2025)
IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. X-Force ID: 198846.
0
Attacker Value
Unknown
CVE-2020-4669
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 184600.
0
Attacker Value
Unknown
CVE-2020-4670
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server. IBM X-Force ID: 186401.
0
Attacker Value
Unknown
CVE-2020-4985
Disclosure Date: May 13, 2021 (last updated November 28, 2024)
IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID: 192642.
0