Back

HIGH

IBM Planning Analytics Local session fixation

Published Jun 1, 2025

Description

IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.

Affected products

Remediation

Vendor solution

It is strongly recommended that you apply the most recent security updates:

IBM Planning Analytics Local - IBM Planning Analytics Workspace 2.1 IBM Planning Analytics Local 2.1.11 is now available for download from Fix Central IBM Planning Analytics Local - IBM Planning Analytics Workspace 2.0 Download IBM Planning Analytics Local v2.0: Planning Analytics Workspace Release 104 from Fix Central

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Jun 1, 2025
Updated Aug 26, 2025
Reserved Apr 15, 2025
CISA Vulnrichment
Updated Jun 2, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ibm
Published Jun 1, 2025
Updated Aug 26, 2025
Exploited since n/a
EUVD-2025-16572