CVE-2020-4527: Medium severity ibm planning analytics cloud vulnerability
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the Secure flag for the session cookie in TLS mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM X-Force ID: 182631.
Other sources
IBM Planning Analytics Administration could allow a remote attacker to obtain sensitive information, caused by the failure to set the Secure flag for the session cookie in TLS mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4527?
The severity of CVE-2020-4527 is medium, with a CVSS score of 5.9.
How does CVE-2020-4527 affect IBM Planning Analytics?
CVE-2020-4527 affects IBM Planning Analytics 2.0.
What is the vulnerability of CVE-2020-4527?
CVE-2020-4527 is a vulnerability that allows a remote attacker to obtain sensitive information by intercepting the session cookie in TLS mode.
How can an attacker exploit CVE-2020-4527?
An attacker can exploit CVE-2020-4527 by intercepting the transmission of the session cookie within an HTTP session.
Is there a fix for CVE-2020-4527?
Yes, a fix for CVE-2020-4527 is available. Please refer to the official IBM support page for instructions on how to fix the vulnerability.