IBM Planning Analytics
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Planning Analytics.
By the Year
In 2026 there have been 0 vulnerabilities in IBM Planning Analytics. Last year, in 2025 Planning Analytics had 8 security vulnerabilities published. Right now, Planning Analytics is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 8 | 6.44 |
| 2024 | 3 | 6.63 |
| 2023 | 2 | 7.60 |
| 2022 | 4 | 6.13 |
| 2021 | 13 | 5.58 |
| 2020 | 5 | 6.32 |
| 2019 | 5 | 6.77 |
It may take a day or so for new Planning Analytics vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Planning Analytics Security Vulnerabilities
IBM Planning Analytics Local 2.1.15 leaks server architecture info
CVE-2025-36437
4.3 - Medium
- December 09, 2025
IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could aid in further attacks against the system.
Generation of Error Message Containing Sensitive Information
IBM Planning Analytics 2.1.02.1.14 Source Code Sensitive Data Leak
CVE-2025-36299
4.3 - Medium
- November 17, 2025
IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system.
Inclusion of Sensitive Information in Source Code
XSS Vulnerability in IBM Planning Analytics Web UI 2.0.02.1.13
CVE-2025-36132
5.4 - Medium
- September 30, 2025
IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM Planning Analytics 2.0-2.1 Authenticated XSS in Web UI
CVE-2025-25044
5.4 - Medium
- June 01, 2025
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM Planning Analytics 2.0/2.1 Local Privileged Pathname Deletion
CVE-2025-33004
6.5 - Medium
- June 01, 2025
IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.
Directory traversal
IBM Planning Analytics 2.0/2.1 Session Hijack: Logout Fails to Invalidate
CVE-2025-33005
8.8 - High
- June 01, 2025
IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
Insufficient Session Expiration
IBM Planning Analytics 2.0-2.1 Vulnerable File Manager T1 Upload Exploit
CVE-2024-25034
8.8 - High
- January 24, 2025
IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in the File Manager T1 process. Attackers can make use of this weakness and upload malicious executable files into the system that can be sent to victims for performing further attacks.
Unrestricted File Upload
IBM Planning Analytics 2.0/2.1: File Upload Vulnerability via Web Interface
CVE-2024-40693
8 - High
- January 24, 2025
IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.
Unrestricted File Upload
IBM Planning Analytics 2.0/2.1 MongoDB Unauth Access Vulnerability
CVE-2024-35143
9.1 - Critical
- August 04, 2024
IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 292420.
Missing Authentication for Critical Function
IBM Planning Analytics XSS in 2.0/2.1 Web UI
CVE-2024-31907
5.4 - Medium
- May 31, 2024
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289889.
XSS
IBM Planning Analytics 2.0/2.1 Stored XSS in Web UI
CVE-2024-31908
5.4 - Medium
- May 31, 2024
IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289890.
XSS
IBM Planning Analytics Local 2.0 RCE via File Upload
CVE-2023-42017
9.8 - Critical
- December 22, 2023
IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious script, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 265567.
Unrestricted File Upload
IBM Planning Analytics Local 2.0 - Stored XSS in Web UI (v2.0)
CVE-2023-28520
5.4 - Medium
- May 12, 2023
IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250454.
XSS
IBM Planning Analytics Local 2.0 LFR via Local Web Page Storage
CVE-2022-22314
3.3 - Low
- September 08, 2022
IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 217371.
IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting
CVE-2021-39047
6.1 - Medium
- June 24, 2022
IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214349.
XSS
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF)
CVE-2022-22339
7.3 - High
- April 08, 2022
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 219736.
SSRF
IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack
CVE-2022-22308
7.8 - High
- February 21, 2022
IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into including remote files with malicious code. IBM X-Force ID: 216891.
Inclusion of Functionality from Untrusted Control Sphere
IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection
CVE-2021-38873
7.8 - High
- November 24, 2021
IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 208396.
Injection
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag
CVE-2021-20526
- October 27, 2021
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 198755.
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser
CVE-2021-29851
4.3 - Medium
- September 01, 2021
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 205527.
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting
CVE-2021-29852
5.4 - Medium
- September 01, 2021
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205528.
XSS
IBM Planning Analytics 2.0 could expose information
CVE-2021-29853
4.3 - Medium
- September 01, 2021
IBM Planning Analytics 2.0 could expose information that could be used to to create attacks by not validating the return values from some methods or functions. IBM X-Force ID: 205529.
Unchecked Return Value
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting
CVE-2021-20477
- June 29, 2021
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196949.
IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to execute malicious and unauthorized actions transmitted from a user
CVE-2021-20580
- June 29, 2021
IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 198241.
IBM Planning Analytics 2.0 could
CVE-2020-4562
5.3 - Medium
- April 26, 2021
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window communication with unrestricted target origin via documentation frames.
Information Disclosure
IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs
CVE-2020-4882
6.1 - Medium
- March 22, 2021
IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 190852.
SSRF
IBM Planning Analytics 2.0 could
CVE-2020-4953
4.3 - Medium
- February 23, 2021
IBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's internal structure by exposing sensitive information in HTTP repsonses. IBM X-Force ID: 192029.
Information Disclosure
IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system
CVE-2020-4871
5.5 - Medium
- January 19, 2021
IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834.
Information Disclosure
IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy
CVE-2020-4873
5.3 - Medium
- January 19, 2021
IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.
Information Disclosure
IBM Planning Analytics 2.0 could
CVE-2020-4881
7.5 - High
- January 19, 2021
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/TLS communication. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 190851.
Origin Validation Error
IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack
CVE-2020-4653
6.1 - Medium
- August 19, 2020
IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Open Redirect
A vulnerability exsists in IBM Planning Analytics 2.0 whereby avatars in Planning Analytics Workspace could be modified by other users without authorization to do so
CVE-2020-4648
6.5 - Medium
- August 19, 2020
A vulnerability exsists in IBM Planning Analytics 2.0 whereby avatars in Planning Analytics Workspace could be modified by other users without authorization to do so. IBM X-Force ID: 186019.
AuthZ
IBM Planning Analytics 2.0 could
CVE-2020-4527
5.9 - Medium
- July 20, 2020
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the Secure flag for the session cookie in TLS mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM X-Force ID: 182631.
Session Fixation
IBM Planning Analytics 2.0 could
CVE-2020-4361
4.3 - Medium
- July 20, 2020
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by disclosing private IP addresses in HTTP responses. IBM X-Force ID: 178766.
Information Disclosure
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user
CVE-2019-4613
8.8 - High
- February 05, 2020
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 168524.
Session Riding
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite
CVE-2019-4716
- December 18, 2019
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
Code Injection
IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal
CVE-2019-4612
8.8 - High
- December 09, 2019
IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 168523.
Unrestricted File Upload
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting
CVE-2019-4611
5.4 - Medium
- December 09, 2019
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168519.
XSS
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting
CVE-2019-4134
6.1 - Medium
- July 02, 2019
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158281.
XSS
IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting
CVE-2018-1933
- May 01, 2019
IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153177.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Planning Analytics or by IBM? Click the Watch button to subscribe.