PublicCVE

CVE-2020-4881

MEDIUM5.9

Description

IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/TLS communication. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 190851.

CVSS breakdown

CVSS 3.0
Attack Complexity
High
Confidentiality
High
Scope
Unchanged
Privileges Required
None
User Interaction
None
Attack Vector
Network
Availability
None
Integrity
None
RC
Changed
RL
O
E
Unchanged

Affected products

Updated 15m ago · 8 sources