Impact
IBM Planning Analytics Local versions 2.1.0 through 2.1.21 contain an open redirect flaw that allows an attacker to craft a URL which redirects users to an arbitrary external website. If this vulnerability is leveraged within single‑sign‑on authentication flows, it can lead to exposure of session tokens and enable attackers to hijack user sessions. The weakness is identified as CWE‑601, an open redirect vulnerability.
Affected Systems
Affected by IBM Planning Analytics Local updated to 2.1.22, the remedy version. All earlier releases from 2.1.0 up to and including 2.1.21 are vulnerable. IBM also states that the Planning Analytics Cloud environment has been remediated and is not impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity risk, while the EPSS score of less than 1% suggests a low likelihood of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating no known mass exploitation. Exploitation typically requires an attacker to supply a specially crafted URL that the victim clicks, potentially leading to session hijacking if the authentication flow is not protected. Since there is an official patch available, the risk can be mitigated by upgrading.
OpenCVE Enrichment