First published: Sat Jan 18 2020(Updated: )
IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Planning Analytics | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4873.
The severity rating of CVE-2020-4873 is medium with a score of 5.3.
An attacker can exploit this vulnerability by taking advantage of the overly permissive CORS policy in IBM Planning Analytics 2.0 to obtain sensitive information.
IBM Planning Analytics 2.0 is affected by CVE-2020-4873.
Yes, IBM has provided a fix for this vulnerability. Please refer to the official IBM support page for more information.