CVE-2025-33005: IBM Planning Analytics Local session fixation
IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
Other sources
IBM Planning Analytics Local does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33005?
The severity of CVE-2025-33005 is classified as medium due to its potential for unauthorized user impersonation.
How do I fix CVE-2025-33005?
To mitigate CVE-2025-33005, ensure that all users are logged out completely to invalidate their sessions before terminating any sessions.
What systems are affected by CVE-2025-33005?
CVE-2025-33005 affects IBM Planning Analytics Local versions 2.0 and 2.1.
What exploit exists for CVE-2025-33005?
CVE-2025-33005 can be exploited by an authenticated user who can impersonate another user if the session is not invalidated after logout.
Is a patch available for CVE-2025-33005?
As of now, there is no specific patch for CVE-2025-33005; users should implement session management best practices to minimize risk.