Page 4 of 53 results (0.002 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

19 Jan 2021 — IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836. IBM Planning Analytics versión 2.0, podría permitir a un atacante obtener información confidencial debido a una política de CORS demasiado permisiva. IBM X-Force ID: 190836 • https://exchange.xforce.ibmcloud.com/vulnerabilities/190836 • CWE-863: Incorrect Authorization •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

19 Jan 2021 — IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834. IBM Planning Analytics versión 2.0, permite que las páginas web se almacenen localmente, por lo que pueden ser leídas por otro usuario en el sistema. IBM X-Force ID: 190834 • https://exchange.xforce.ibmcloud.com/vulnerabilities/190834 • CWE-922: Insecure Storage of Sensitive Information •

CVSS: 6.5EPSS: 0%CPEs: 3EXPL: 0

18 Dec 2020 — IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 188898. IBM Planning Analytics versión 2.0, es vulnerable a un ataque de tipo cross-site request forgery, lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas por un usuario en el que el sitio web confía. IBM X-Force ID: 188898 • https://exchange.xforce.ibmcloud.com/vulnerabilities/188898 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

03 Nov 2020 — IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions. IBM X-Force ID: 186022. IBM Planning Analytics Local versión 2.0.9.2 e IBM Planning Analytics Workspace versión 57, podrían exponer datos a usuarios sin privilegios al no invalidar las sesiones de usuario TM1Web. IBM X-Force ID: 186022 • https://exchange.xforce.ibmcloud.com/vulnerabilities/186022 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 0

19 Aug 2020 — IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM Planning Analytics versión 2.0, podría permitir a un atacan... • https://exchange.xforce.ibmcloud.com/vulnerabilities/186082 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

19 Aug 2020 — A vulnerability exsists in IBM Planning Analytics 2.0 whereby avatars in Planning Analytics Workspace could be modified by other users without authorization to do so. IBM X-Force ID: 186019. Se presenta una vulnerabilidad en IBM Planning Analytics versión 2.0, por la cual los avatares en Planning Analytics Workspace podrían ser modificados por otros usuarios sin autorización para hacerlo. IBM X-Force ID: 186019. • https://exchange.xforce.ibmcloud.com/vulnerabilities/186019 •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

29 Jul 2020 — IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 185717. IBM Planning Analytics Local versiones 2.0.0 hasta 2.0.9.1, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Inter... • https://exchange.xforce.ibmcloud.com/vulnerabilities/185717 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

29 Jul 2020 — IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 185716. IBM Planning Analytics Local versiones 2.0.0 hasta 2.0.9.1, podría permitir a un atacante remoto secuestrar la acción de clic de la víctima. Al persuadir a una víct... • https://exchange.xforce.ibmcloud.com/vulnerabilities/185716 • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

20 Jul 2020 — IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the Secure flag for the session cookie in TLS mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM X-Force ID: 182631. IBM Planning Analytics versión 2.0, podría permitir a un atacante remoto obtener información confidencial, causado por el fallo al ajustar el flag Secure para ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/182631 • CWE-384: Session Fixation •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

20 Jul 2020 — IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by disclosing private IP addresses in HTTP responses. IBM X-Force ID: 178766. IBM Planning Analytics versión 2.0, podría permitir a un atacante remoto obtener información confidencial al divulgar direcciones IP privadas en respuestas HTTP. IBM X-Force ID: 178766 • https://exchange.xforce.ibmcloud.com/vulnerabilities/178766 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •