CVE-2020-4881: High severity ibm planning analytics cloud vulnerability
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/TLS communication. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 190851.
Other sources
IBM Planning Analytics ould allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/TLS communication. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-4881.
What is the severity level of CVE-2020-4881?
The severity level of CVE-2020-4881 is high (7.5).
What is the affected software?
The affected software is IBM Planning Analytics version 2.0.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by sending a specially-crafted request to obtain sensitive information.
Is there a fix available for this vulnerability?
Yes, IBM has provided a fix for this vulnerability. Please refer to the references for more information.