PT-2021-12207 · Ibm · Ibm Planning Analytics

Published

2021-01-19

·

Updated

2021-01-22

·

CVE-2020-4881

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Planning Analytics version 2.0
Description The issue is caused by the lack of server hostname verification for SSL/TLS communication, allowing a remote attacker to obtain sensitive information by sending a specially-crafted request.
Recommendations For IBM Planning Analytics version 2.0, consider disabling SSL/TLS communication until a patch is available, or restrict access to sensitive information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4881

Affected Products

Ibm Planning Analytics