Sensitive Information Exposure in IBM Planning Analytics Local
CVE-2025-36299

4.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
17 November 2025

What is CVE-2025-36299?

IBM Planning Analytics Local versions 2.1.0 through 2.1.14 have a vulnerability that allows sensitive information to be stored in the source code. This flaw could be leveraged by attackers to exploit the system further, leading to potential data breaches and unauthorized access to critical information. Organizations using these versions are advised to review their security measures and consider upgrading to protect against this exposure.

Affected Version(s)

IBM Planning Analytics Local 2.1.0 <= 2.1.14

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36299 : Sensitive Information Exposure in IBM Planning Analytics Local