Description
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 219736.
CVSS breakdown
CVSS 3.0
Attack Complexity
Low
User Interaction
None
Confidentiality
Low
Scope
Unchanged
Availability
Low
Attack Vector
Network
Integrity
None
Privileges Required
None
RL
O
E
Unchanged
RC
Changed
Affected products
- ibm / planning_analytics2.0 – 2.0
Updated 15m ago · 8 sources