Published: 01/05/2019 Updated: 08/05/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

IBM Planning Analytics 2.0 up to and including 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153177.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm planning analytics

Vendor Advisories

There is a vulnerability in IBM® Runtime Environment Java™ Version 8 used by IBM Planning Analytics This issue was disclosed as part of the IBM Java SDK updates in October 2018 As of version 206, IBM Planning Analytics is no longer compatible with IBM® Runtime Environment Java™ Version 7 IBM Planning Analytics 207 (Windows) will instal ...