Impact
IBM Planning Analytics 2.0 and 2.1 Local are vulnerable to cross‑site request forgery, enabling an attacker to trigger state‑changing actions on the site with the credentials of a trusted user. The flaw can lead to unauthorized access to or modification of data and configuration settings, potentially compromising both confidentiality and integrity on the affected system.
Affected Systems
The affected products are IBM Planning Analytics Local versions 2.0 and 2.1, specifically 2.1.0 through 2.1.22. Version 2.1.23 has been released to remediate the issue. The IBM Planning Analytics Cloud environment has been remediated and is not affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, classifying it as high severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is a user who, while authenticated to the Planning Analytics web interface, is tricked into visiting a malicious site that submits forged requests. Successful exploitation would require a valid session cookie to carry out arbitrary actions on the behalf of the victim.
OpenCVE Enrichment