CVE-2024-31908: IBM Planning Analytics Local cross-site scripting
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289890.
Other sources
IBM Planning Analytics Local is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31908?
The severity of CVE-2024-31908 is rated as high due to the potential for credentials disclosure through stored cross-site scripting.
How do I fix CVE-2024-31908?
To fix CVE-2024-31908, it is recommended to update IBM Planning Analytics Local to version 2.2 or later.
What are the affected versions for CVE-2024-31908?
The affected versions for CVE-2024-31908 include IBM Planning Analytics Local 2.0 and 2.1.
What type of vulnerability is CVE-2024-31908?
CVE-2024-31908 is a stored cross-site scripting vulnerability that allows attackers to inject arbitrary JavaScript code.
Can CVE-2024-31908 be exploited in a trusted session?
Yes, CVE-2024-31908 can be exploited within a trusted session, potentially leading to credential disclosure.