CVE-2021-20526: low-severity vulnerability in IBM Planning Analytics
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.7epss 1.1%
exploitation probability
1.1%top 35% of all CVEs
observed exploitation
nono source reports it
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 198755.
CVSS:3.0/AV:N/PR:N/S:U/I:N/C:L/A:N/UI:N/AC:H/E:U/RL:O/RC:C
Affected products
IBM · Planning AnalyticsRelated CVEs — IBM Planning Analytics
In the same product, most dangerous first.