IBM Planning Analytics Local 2.0.0-2.0.106/2.1.0-2.1.13 Input Validation Priv Esc
CVE-2025-36262 Published on September 30, 2025
IBM Planning Analytics Local information disclosure
IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13
could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.
Vulnerability Analysis
CVE-2025-36262 is exploitable with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Improper Validation of Syntactic Correctness of Input
The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
Products Associated with CVE-2025-36262
Want to know whenever a new CVE is published for IBM Planning Analytics Local? stack.watch will email you.
Affected Versions
IBM Planning Analytics Local:- Version 2.0.0, <= 2.0.106 is affected.
- Version 2.1.0, <= 2.1.13 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.