First published: Thu Apr 07 2022(Updated: )
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 219736.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Planning Analytics | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-22339.
The title of the vulnerability is 'IBM Planning Analytics is vulnerable to server-side request forgery (SSRF).'
Server-side request forgery (SSRF) is a vulnerability that allows an attacker to make unauthorized requests from the vulnerable server.
CVE-2022-22339 allows an authenticated attacker to send unauthorized requests from IBM Planning Analytics, potentially leading to network enumeration or facilitating other attacks.
The severity of vulnerability CVE-2022-22339 is high with a severity value of 7.3.
To fix the vulnerability CVE-2022-22339 in IBM Planning Analytics 2.0, apply the necessary security patches or updates provided by IBM.