PT-2025-40022 · Ibm · Ibm Planning Analytics Local

Published

2025-09-30

·

Updated

2025-10-01

·

CVE-2025-36132

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Planning Analytics Local versions 2.0.0 through 2.0.106 IBM Planning Analytics Local versions 2.1.0 through 2.1.13
Description An authenticated user can embed arbitrary JavaScript code in the Web UI, potentially altering intended functionality and leading to credentials disclosure within a trusted session. The issue involves cross-site scripting.
Recommendations Update IBM Planning Analytics Local to a version later than 2.0.106 Update IBM Planning Analytics Local to a version later than 2.1.13

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-16311
CVE-2025-36132

Affected Products

Ibm Planning Analytics Local