CVE-2023-26026: IBM Planning Analytics Cartridge for Cloud Pak for Data information disclosure
IBM Planning Analytics connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database.
Other sources
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-26026.
What is the severity of CVE-2023-26026?
The severity of CVE-2023-26026 is high with a score of 7.5.
What software is affected by CVE-2023-26026?
The affected software includes IBM Planning Analytics Cartridge for IBM Cloud Pak for Data 4.0.
What is the impact of CVE-2023-26026?
CVE-2023-26026 exposes sensitive information in logs, which could lead to further attacks.
Are there any references for CVE-2023-26026?
Yes, you can find references for CVE-2023-26026 at IBM X-Force ID 247896, IBM support pages, and IBM X-Force ID 247905.