CVE-2020-4873: Medium severity ibm planning analytics cloud vulnerability
Published Jan 18, 2020
·Updated
IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.
Other sources
IBM Planning Analytics could allow an attacker to obtain sensitive information due to an overly permissive CORS policy.
Affected Software
1 affected component
IBM Planning Analytics=2.0
Remediation
Patch Available
Event History
Jan 18, 2020
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Jan 19, 2021
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-4873.
2
What is the severity rating of CVE-2020-4873?
The severity rating of CVE-2020-4873 is medium with a score of 5.3.
3
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by taking advantage of the overly permissive CORS policy in IBM Planning Analytics 2.0 to obtain sensitive information.
4
What software is affected by CVE-2020-4873?
IBM Planning Analytics 2.0 is affected by CVE-2020-4873.
5
Is there a fix available for CVE-2020-4873?
Yes, IBM has provided a fix for this vulnerability. Please refer to the official IBM support page for more information.