VendorsIBMplanning_analytics_localany version
Vulnerabilities

IBM Planning Analytics Local any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2024-35143
IBM Planning Analytics Local missing authentication
Published 2024-08-04 · Analyzed
9.1EPSS 0.004
CVE-2025-36357
IBM Planning Analytics Local Directory Traversal
Published 2025-11-17 · Analyzed
8.0EPSS 0.008
CVE-2020-4367
IBM Planning Analytics Local 2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179001.
Published 2020-06-02 · Modified
7.5EPSS 0.008
CVE-2026-10545
IBM Planning Analytics Local is affected by Open Redirect
Published 2026-07-30 · Analyzed
7.5EPSS 0.004
CVE-2026-13365
IBM Planning Analytics Local is affected by security vulnerabilities
Published 2026-08-13 · Analyzed
7.1EPSS 0.002
CVE-2026-1267
IBM Planning Analytics Information Disclosure
Published 2026-03-17 · Analyzed
6.5EPSS 0.003
CVE-2020-4644
IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 185716.
Published 2020-07-29 · Modified
6.1EPSS 0.012
CVE-2018-1676
IBM Planning Analytics 2.0.0 through 2.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145118.
Published 2018-07-06 · Modified
6.1EPSS 0.009
CVE-2020-4503
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182283.
Published 2020-06-02 · Modified
6.1EPSS 0.008
CVE-2020-4366
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178965.
Published 2020-06-02 · Modified
6.1EPSS 0.007
CVE-2025-14806
IBM Planning Analytics Information Disclosure
Published 2026-03-17 · Analyzed
5.7EPSS 0.003
CVE-2020-4360
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178765.
Published 2020-06-02 · Modified
5.4EPSS 0.007
CVE-2020-4645
IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 185717.
Published 2020-07-29 · Modified
5.4EPSS 0.006
CVE-2020-4431
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180761.
Published 2020-06-02 · Modified
5.4EPSS 0.006
CVE-2020-4306
IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176735.
Published 2020-05-29 · Modified
5.4EPSS 0.006
CVE-2025-36132
IBM Planning Analytics Local cross-site scripting
Published 2025-09-30 · Analyzed
5.4EPSS 0.002
CVE-2025-36262
IBM Planning Analytics Local information disclosure
Published 2025-09-30 · Analyzed
4.9EPSS 0.003
CVE-2020-4649
IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions. IBM X-Force ID: 186022.
Published 2020-11-03 · Modified
4.3EPSS 0.008
CVE-2025-36299
IBM Planning Analytics Information Disclosure
Published 2025-11-17 · Analyzed
4.3EPSS 0.002
CVE-2025-36437
IBM Planning Analytics Local is vulnerable to disclosing sensitive information
Published 2025-12-09 · Analyzed
4.3EPSS 0.002