PT-2021-12208 · Ibm · Ibm Planning Analytics

Published

2021-03-22

·

Updated

2021-03-24

·

CVE-2020-4882

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Planning Analytics version 2.0
Description The issue allows for a Server-Side Request Forgery (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system.
Recommendations For IBM Planning Analytics version 2.0, consider restricting the construction of URLs from user-controlled data to minimize the risk of exploitation. As a temporary workaround, consider implementing additional validation and sanitization of user input to prevent malicious URL constructions.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4882

Affected Products

Ibm Planning Analytics