Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2024-31908

Disclosure Date: May 31, 2024 (last updated January 13, 2025)
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289890.
Attacker Value
Unknown

CVE-2024-31907

Disclosure Date: May 31, 2024 (last updated January 13, 2025)
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289889.
Attacker Value
Unknown

CVE-2024-31889

Disclosure Date: May 31, 2024 (last updated January 13, 2025)
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 288136.
Attacker Value
Unknown

CVE-2023-28520

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250454.
Attacker Value
Unknown

CVE-2021-29739

Disclosure Date: August 09, 2021 (last updated February 23, 2025)
IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. X-Force ID: 198846.
Attacker Value
Unknown

CVE-2020-4669

Disclosure Date: May 14, 2021 (last updated February 22, 2025)
IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 184600.
Attacker Value
Unknown

CVE-2020-4670

Disclosure Date: May 14, 2021 (last updated February 22, 2025)
IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server. IBM X-Force ID: 186401.
Attacker Value
Unknown

CVE-2020-4985

Disclosure Date: May 13, 2021 (last updated November 28, 2024)
IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID: 192642.