Description
IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions.
Published: 2026-07-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Planning Analytics Local versions 2.1.0 through 2.1.21 contain an open redirect flaw that allows an attacker to craft a URL which redirects users to an arbitrary external website. If this vulnerability is leveraged within single‑sign‑on authentication flows, it can lead to exposure of session tokens and enable attackers to hijack user sessions. The weakness is identified as CWE‑601, an open redirect vulnerability.

Affected Systems

Affected by IBM Planning Analytics Local updated to 2.1.22, the remedy version. All earlier releases from 2.1.0 up to and including 2.1.21 are vulnerable. IBM also states that the Planning Analytics Cloud environment has been remediated and is not impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity risk, while the EPSS score of less than 1% suggests a low likelihood of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating no known mass exploitation. Exploitation typically requires an attacker to supply a specially crafted URL that the victim clicks, potentially leading to session hijacking if the authentication flow is not protected. Since there is an official patch available, the risk can be mitigated by upgrading.

Generated by OpenCVE AI on August 3, 2026 at 10:36 UTC.

Remediation

Vendor Solution

It is strongly recommended that you apply the most recent security updates:  Affected Product(s)Version(s)FixIBM Planning Analytics Local2.1.0 - 2.1.21 IBM Planning Analytics Local 2.1.22 is now available for download from Fix Central https://w3.ibm.com/w3publisher/capa-release-announcements/2026-releases/pa-2026-releases IBM Planning Analytics Cloud environment has been remediated.


OpenCVE Recommended Actions

  • Elevate the IBM Planning Analytics Local installation to version 2.1.22 or later, which removes support for the vulnerable redirect mechanism.
  • Examine SSO authentication workflows for any remaining external redirects and remove or whitelist the domains that are allowed; enforce a strict redirect policy to internal trusted sites only.
  • Implement monitoring of redirect telemetry to detect unexpected outbound redirects from the application and alert administrators to suspicious activity.

Generated by OpenCVE AI on August 3, 2026 at 10:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:planning_analytics_local:*:*:*:*:*:*:*:*

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions.
Title IBM Planning Analytics Local is affected by Open Redirect
First Time appeared Ibm
Ibm planning Analytics Local
Weaknesses CWE-601
CPEs cpe:2.3:a:ibm:planning_analytics_local:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:planning_analytics_local:2.1.21:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm planning Analytics Local
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Planning Analytics Local
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T18:32:22.380Z

Reserved: 2026-06-01T12:53:46.014Z

Link: CVE-2026-10545

cve-icon Vulnrichment

Updated: 2026-07-30T18:32:13.111Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T19:17:01.597

Modified: 2026-08-12T19:55:16.987

Link: CVE-2026-10545

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:45:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')