First published: Tue Jun 29 2021(Updated: )
IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 198241.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Planning Analytics | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this IBM Planning Analytics vulnerability is CVE-2021-20580.
The severity level of CVE-2021-20580 is medium, with a severity value of 4.3.
Cross-site request forgery (CSRF) is a type of security vulnerability that allows an attacker to trick a user into performing unwanted actions on a website without their consent.
With this vulnerability, an attacker could execute malicious and unauthorized actions through a user that the website trusts in IBM Planning Analytics.
To fix the CSRF vulnerability in IBM Planning Analytics, apply the recommended security patches or updates provided by IBM. It is also recommended to implement additional security measures, such as implementing CSRF tokens, to mitigate the risk of CSRF attacks.