Cross-Site Scripting Vulnerability in IBM Planning Analytics Web UI
CVE-2021-29852

5.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 September 2021

Summary

IBM Planning Analytics 2.0 is susceptible to a cross-site scripting vulnerability that permits the injection of arbitrary JavaScript code into its Web UI. This flaw can be exploited by an attacker to modify the site's functionality and potentially expose sensitive user credentials within a trusted session, compromising the security of affected systems. For further details, refer to IBM's support page and the IBM X-Force vulnerability database.

Affected Version(s)

Planning Analytics Local 2.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.