Skip to main content

Vendor/product archive

ibm / planning_analytics_local CVEs

Beta · best-effort

30 CVEs tagged to ibm / planning_analytics_local2 Critical, 3 High, 25 Medium, 0 Low, 0 Unrated.

CVE-2026-1267

Published Mar 17, 2026

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities due to lack of proper access…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14806

Published Mar 17, 2026

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly ca…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36437

Published Dec 9, 2025

IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could aid in further attacks against the system.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36262

Published Sep 30, 2025

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive inf…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36132

Published Sep 30, 2025

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-33005

Published Jun 1, 2025

IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-33004

Published Jun 1, 2025

IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2896

Published Jun 1, 2025

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI th…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25044

Published Jun 1, 2025

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI th…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-31908

Published May 31, 2024

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alteri…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31907

Published May 31, 2024

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31889

Published May 31, 2024

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28520

Published May 12, 2023

IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29739

Published Aug 10, 2021

IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. X-Force ID: 198846.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4985

Published May 14, 2021

IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID: 192642.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4649

Published Nov 3, 2020

IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions. IBM X-Force ID: 186…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4645

Published Jul 29, 2020

IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4644

Published Jul 29, 2020

IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site,…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4503

Published Jun 2, 2020

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4431

Published Jun 2, 2020

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 30 CVEsPage 1 of 2