VendorsIBMplanning_analytics_localall versions
Vulnerabilities

IBM Planning Analytics Local

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

32CVEs
CVE-2020-4670
IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server. IBM X-Force ID: 186401.
Published 2021-05-17 · Modified
9.1EPSS 0.024
CVE-2020-4669
IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 184600.
Published 2021-05-17 · Modified
9.1EPSS 0.019
CVE-2024-35143
IBM Planning Analytics Local missing authentication
Published 2024-08-04 · Analyzed
9.1EPSS 0.004
CVE-2025-33005
IBM Planning Analytics Local session fixation
Published 2025-06-01 · Analyzed
8.8EPSS 0.002
CVE-2025-36357
IBM Planning Analytics Local Directory Traversal
Published 2025-11-17 · Analyzed
8.0EPSS 0.008
CVE-2020-4985
IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID: 192642.
Published 2021-05-14 · Modified
7.5EPSS 0.010
CVE-2020-4367
IBM Planning Analytics Local 2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179001.
Published 2020-06-02 · Modified
7.5EPSS 0.008
CVE-2026-10545
IBM Planning Analytics Local is affected by Open Redirect
Published 2026-07-30 · Analyzed
7.5EPSS 0.004
CVE-2026-13365
IBM Planning Analytics Local is affected by security vulnerabilities
Published 2026-08-13 · Analyzed
7.1EPSS 0.002
CVE-2025-33004
IBM Planning Analytics Local path traversal
Published 2025-06-01 · Analyzed
6.5EPSS 0.005
CVE-2026-1267
IBM Planning Analytics Information Disclosure
Published 2026-03-17 · Analyzed
6.5EPSS 0.003
CVE-2023-28520
IBM Planning Analytics Local cross-site scripting
Published 2023-05-12 · Modified
6.4EPSS 0.004
CVE-2024-31908
IBM Planning Analytics Local cross-site scripting
Published 2024-05-31 · Analyzed
6.4EPSS 0.002
CVE-2020-4644
IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 185716.
Published 2020-07-29 · Modified
6.1EPSS 0.012
CVE-2018-1676
IBM Planning Analytics 2.0.0 through 2.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145118.
Published 2018-07-06 · Modified
6.1EPSS 0.009
CVE-2020-4503
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182283.
Published 2020-06-02 · Modified
6.1EPSS 0.008
CVE-2020-4366
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178965.
Published 2020-06-02 · Modified
6.1EPSS 0.007
CVE-2025-14806
IBM Planning Analytics Information Disclosure
Published 2026-03-17 · Analyzed
5.7EPSS 0.003
CVE-2020-4360
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178765.
Published 2020-06-02 · Modified
5.4EPSS 0.007
CVE-2020-4306
IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176735.
Published 2020-05-29 · Modified
5.4EPSS 0.006
CVE-2020-4645
IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 185717.
Published 2020-07-29 · Modified
5.4EPSS 0.006
CVE-2020-4431
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180761.
Published 2020-06-02 · Modified
5.4EPSS 0.006
CVE-2024-31889
IBM Planning Analytics Local cross-site scripting
Published 2024-05-31 · Analyzed
5.4EPSS 0.002
CVE-2024-31907
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289889.
Published 2024-05-31 · Analyzed
5.4EPSS 0.002
CVE-2025-25044
IBM Planning Analytics Local cross-site scripting
Published 2025-06-01 · Analyzed
5.4EPSS 0.002
CVE-2025-2896
IBM Planning Analytics Local cross-site scripting
Published 2025-06-01 · Analyzed
5.4EPSS 0.002
CVE-2025-36132
IBM Planning Analytics Local cross-site scripting
Published 2025-09-30 · Analyzed
5.4EPSS 0.002
CVE-2021-29739
IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. X-Force ID: 198846.
Published 2021-08-10 · Modified
4.9EPSS 0.011
CVE-2025-36262
IBM Planning Analytics Local information disclosure
Published 2025-09-30 · Analyzed
4.9EPSS 0.003
CVE-2020-4649
IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions. IBM X-Force ID: 186022.
Published 2020-11-03 · Modified
4.3EPSS 0.008
CVE-2025-36437
IBM Planning Analytics Local is vulnerable to disclosing sensitive information
Published 2025-12-09 · Analyzed
4.3EPSS 0.002
CVE-2025-36299
IBM Planning Analytics Information Disclosure
Published 2025-11-17 · Analyzed
4.3EPSS 0.002