Vulnerabilities > IBM > Planning Analytics Local

DATE CVE VULNERABILITY TITLE RISK
2024-08-04 CVE-2024-35143 Missing Authentication for Critical Function vulnerability in IBM products
IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server.
network
low complexity
ibm CWE-306
critical
9.1
2024-05-31 CVE-2024-31889 Unspecified vulnerability in IBM Planning Analytics Local 2.0.0/2.1.0
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting.
network
low complexity
ibm
5.4
2024-05-31 CVE-2024-31907 Unspecified vulnerability in IBM Planning Analytics Local 2.0.0/2.1.0
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting.
network
low complexity
ibm
5.4
2024-05-31 CVE-2024-31908 Unspecified vulnerability in IBM Planning Analytics Local 2.0.0/2.1.0
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting.
network
low complexity
ibm
5.4
2023-05-12 CVE-2023-28520 Unspecified vulnerability in IBM Planning Analytics Local 2.0.0
IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting.
network
low complexity
ibm
5.4
2021-08-10 CVE-2021-29739 Unchecked Return Value vulnerability in IBM Planning Analytics Local 2.0.0
IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.
network
low complexity
ibm CWE-252
4.9
2021-05-17 CVE-2020-4669 Missing Authorization vulnerability in IBM Planning Analytics Cloud and Planning Analytics Local
IBM Planning Analytics Local 2.0 connects to a MongoDB server.
network
low complexity
ibm CWE-862
critical
9.1
2021-05-17 CVE-2020-4670 Missing Authentication for Critical Function vulnerability in IBM Planning Analytics Cloud and Planning Analytics Local
IBM Planning Analytics Local 2.0 connects to a Redis server.
network
low complexity
ibm CWE-306
critical
9.1
2021-05-14 CVE-2020-4985 Unspecified vulnerability in IBM Planning Analytics Local 2.0.0
IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query.
network
low complexity
ibm
7.5
2020-11-03 CVE-2020-4649 Information Exposure vulnerability in IBM Planning Analytics Local
IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions.
network
low complexity
ibm CWE-200
4.3