CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 2Planning Analytics Local Planning Analytics WorkspaceJun 17, 2026 Nov 17, 2025 N/A· v4 8.0 HIGH· v3 N/A· v2 IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences t...Show more |
1Ibm 2Planning Analytics Local Planning Analytics WorkspaceJun 17, 2026 Nov 17, 2025 N/A· v4 4.3 MEDIUM· v3 N/A· v2 IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system. |
1Ibm 2Planning Analytics Local Planning Analytics WorkspaceJun 17, 2026 Aug 4, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authenticat...Show more |
IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 217371. |
1Ibm 1Planning Analytics Workspace Jun 17, 2026 Apr 25, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066. |
1Ibm 1Planning Analytics Workspace Jun 17, 2026 Apr 25, 2022 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system a...Show more |