CVE-2024-31907: XSS
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289889.
Other sources
IBM Planning Analytics Local is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31907?
CVE-2024-31907 has a medium severity rating due to the potential for cross-site scripting attacks.
How do I fix CVE-2024-31907?
To fix CVE-2024-31907, update IBM Planning Analytics Local to a version above 2.1.
What types of attacks are possible with CVE-2024-31907?
CVE-2024-31907 allows attackers to execute arbitrary JavaScript code within the Web UI, potentially disclosing user credentials.
Which versions of IBM Planning Analytics Local are affected by CVE-2024-31907?
CVE-2024-31907 affects IBM Planning Analytics Local versions 2.0 and 2.1.
Is user interaction required for CVE-2024-31907 to be exploited?
Yes, user interaction is typically required to exploit CVE-2024-31907 through malicious content embedded in web pages.