First published: Sat Jan 18 2020(Updated: )
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/TLS communication. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 190851.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Planning Analytics | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-4881.
The severity level of CVE-2020-4881 is high (7.5).
The affected software is IBM Planning Analytics version 2.0.
A remote attacker can exploit this vulnerability by sending a specially-crafted request to obtain sensitive information.
Yes, IBM has provided a fix for this vulnerability. Please refer to the references for more information.