Sensitive Information Disclosure in IBM Planning Analytics
CVE-2021-20526
3.7LOW
What is CVE-2021-20526?
IBM Planning Analytics 2.0 is affected by a vulnerability that allows remote attackers to access sensitive information due to the lack of the HTTPOnly flag on cookies. This oversight can enable malicious actors to retrieve confidential data, compromising the security of users' session identifiers. Users of IBM Planning Analytics should implement necessary security measures to mitigate the risk associated with this vulnerability. For detailed information, refer to the IBM support page and the X-Force vulnerability database.
Affected Version(s)
Planning Analytics 2.0