Description
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/TLS communication. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 190851.
CVSS breakdown
CVSS 3.0
Attack Complexity
High
Confidentiality
High
Scope
Unchanged
Privileges Required
None
User Interaction
None
Attack Vector
Network
Availability
None
Integrity
None
RC
Changed
RL
O
E
Unchanged
Affected products
- ibm / planning_analytics2.0 – 2.0
Updated 15m ago · 8 sources