IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13

could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.
Fixes

Solution

It is strongly recommended that you apply the most recent security updates:   Affected Product(s)VersionFixIBM Planning Analytics Local - IBM Planning Analytics Workspace2.1.0 - 2.1.13 IBM Planning Analytics Local 2.1.14 is now available for download from Fix Central https://www.ibm.com/support/pages/node/7245803 IBM Planning Analytics Local - IBM Planning Analytics Workspace2.0.0 - 2.0.106 Download IBM Planning Analytics Local v2.0: Planning Analytics Workspace Release 107 from Fix Central https://www.ibm.com/support/pages/node/7245802 IBM Planning Analytics Cloud and Planning Analytics as a Service environments have been remediated.


Workaround

No workaround given by the vendor.

History

Tue, 30 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Sep 2025 19:45:00 +0000

Type Values Removed Values Added
Description IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.
Title IBM Planning Analytics Local information disclosure
First Time appeared Ibm
Ibm planning Analytics Local
Weaknesses CWE-1286
CPEs cpe:2.3:a:ibm:planning_analytics_local:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:planning_analytics_local:2.0.106:*:*:*:*:*:*:*
cpe:2.3:a:ibm:planning_analytics_local:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:planning_analytics_local:2.1.13:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm planning Analytics Local
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-09-30T20:41:05.565Z

Reserved: 2025-04-15T21:16:45.855Z

Link: CVE-2025-36262

cve-icon Vulnrichment

Updated: 2025-09-30T20:40:39.258Z

cve-icon NVD

Status : Received

Published: 2025-09-30T20:15:37.993

Modified: 2025-09-30T20:15:37.993

Link: CVE-2025-36262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.