Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm planning analytics 2.0 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2021-29851
IBM Planning Analytics 2.0 could allow a remote malicious user to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 205527.
Ibm Planning Analytics 2.0
5.4
CVSSv3
CVE-2021-29852
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 2055...
Ibm Planning Analytics 2.0
4.3
CVSSv3
CVE-2021-29853
IBM Planning Analytics 2.0 could expose information that could be used to to create attacks by not validating the return values from some methods or functions. IBM X-Force ID: 205529.
Ibm Planning Analytics 2.0
4.9
CVSSv3
CVE-2021-29739
IBM Planning Analytics Local 2.0 could allow a remote malicious user to obtain sensitive information when a stack trace is returned in the browser. X-Force ID: 198846.
Ibm Planning Analytics Local 2.0.0
5.4
CVSSv3
CVE-2021-20477
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 1969...
Ibm Planning Analytics 2.0
4.3
CVSSv3
CVE-2021-20580
IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an malicious user to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 198241.
Ibm Planning Analytics 2.0
9.1
CVSSv3
CVE-2020-4669
IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database....
Ibm Planning Analytics Cloud 2.0.0
Ibm Planning Analytics Local 2.0.0
9.1
CVSSv3
CVE-2020-4670
IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server. IBM X-Force ID: ...
Ibm Planning Analytics Local 2.0.0
Ibm Planning Analytics Cloud 2.0.0
7.5
CVSSv3
CVE-2020-4985
IBM Planning Analytics Local 2.0 could allow an malicious user to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID: 192642.
Ibm Planning Analytics Local 2.0.0
5.3
CVSSv3
CVE-2020-4562
IBM Planning Analytics 2.0 could allow a remote malicious user to obtain sensitive information by allowing cross-window communication with unrestricted target origin via documentation frames.
Ibm Planning Analytics 2.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »