CVE-2021-20477: XSS
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196949.
Other sources
IBM Planning Analytics Local is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-20477.
What is the severity of CVE-2021-20477?
The severity of CVE-2021-20477 is medium.
What software is affected by CVE-2021-20477?
IBM Planning Analytics 2.0 is affected by CVE-2021-20477.
What is the impact of CVE-2021-20477?
CVE-2021-20477 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Is there a fix for CVE-2021-20477?
Yes, IBM has released a fix for CVE-2021-20477. Please refer to IBM's support page for more information.