Cross-Site Scripting Vulnerability in IBM Planning Analytics Web UI
CVE-2021-29852
5.4MEDIUM
What is CVE-2021-29852?
IBM Planning Analytics 2.0 is susceptible to a cross-site scripting vulnerability that permits the injection of arbitrary JavaScript code into its Web UI. This flaw can be exploited by an attacker to modify the site's functionality and potentially expose sensitive user credentials within a trusted session, compromising the security of affected systems. For further details, refer to IBM's support page and the IBM X-Force vulnerability database.
Affected Version(s)
Planning Analytics Local 2.0