Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.17% | — | IBM Planning Analytics Local | 13/8/2026 | 17/8/2026 | IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Analizada | Alta (7.5) | 0.38% | — | IBM Planning Analytics Local | 30/7/2026 | 12/8/2026 | IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions. | |
| Analizada | Media (6.5) | 0.33% | — | IBM Planning Analytics Local | 17/3/2026 | 17/6/2026 | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities due to lack of proper access controls. | |
| Analizada | Media (5.7) | 0.29% | — | IBM Planning Analytics Local | 17/3/2026 | 17/6/2026 | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly cacheable resources. | |
| Analizada | Media (4.3) | 0.21% | — | IBM Planning Analytics Local | 9/12/2025 | 17/6/2026 | IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could aid in further attacks against the system. | |
| Analizada | Alta (8) | 0.82% | — | IBM Planning Analytics LocalIBM Planning Analytics Workspace | 17/11/2025 | 17/6/2026 | IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences to view, read, or write arbitrary files on the system. | |
| Analizada | Media (4.3) | 0.21% | — | IBM Planning Analytics LocalIBM Planning Analytics Workspace | 17/11/2025 | 17/6/2026 | IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system. | |
| Analizada | Media (4.9) | 0.30% | — | IBM Planning Analytics Local | 30/9/2025 | 17/6/2026 | IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input. | |
| Analizada | Media (5.4) | 0.19% | — | IBM Planning Analytics Local | 30/9/2025 | 17/6/2026 | IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Analizada | Alta (8.8) | 0.25% | — | IBM Planning Analytics Local | 1/6/2025 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (6.5) | 0.46% | — | IBM Planning Analytics Local | 1/6/2025 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction. | |
| Analizada | Media (5.4) | 0.20% | — | IBM Planning Analytics Local | 1/6/2025 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.21% | — | IBM Planning Analytics Local | 1/6/2025 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Crítica (9.1) | 0.43% | — | IBM Planning Analytics WorkspaceIBM Planning Analytics Local | 4/8/2024 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 292420. | |
| Analizada | Media (5.4) | 0.25% | — | IBM Planning Analytics Local | 31/5/2024 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289890. | |
| Analizada | Media (5.4) | 0.25% | — | IBM Planning Analytics Local | 31/5/2024 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289889. | |
| Analizada | Media (5.4) | 0.25% | — | IBM Planning Analytics Local | 31/5/2024 | 17/6/2026 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 288136. | |
| Modificada | Media (5.4) | 0.35% | — | IBM Planning Analytics Local | 12/5/2023 | 17/6/2026 | IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 250454. | |
| Modificada | Media (4.9) | 1.1% | — | IBM Planning Analytics Local | 10/8/2021 | 17/6/2026 | IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. X-Force ID: 198846. | |
| Modificada | Crítica (9.1) | 2.4% | — | IBM Planning Analytics CloudIBM Planning Analytics Local | 17/5/2021 | 17/6/2026 | IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server. IBM X-Force ID: 186401. | |
| Modificada | Crítica (9.1) | 1.9% | — | IBM Planning Analytics CloudIBM Planning Analytics Local | 17/5/2021 | 17/6/2026 | IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 184600. | |
| Modificada | Alta (7.5) | 0.98% | — | IBM Planning Analytics Local | 14/5/2021 | 17/6/2026 | IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID: 192642. | |
| Modificada | Media (4.3) | 0.82% | — | IBM Planning Analytics Local | 3/11/2020 | 17/6/2026 | IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions. IBM X-Force ID: 186022. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Planning Analytics Local | 29/7/2020 | 17/6/2026 | IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 185717. | |
| Modificada | Media (5.4) | 1.2% | — | IBM Planning Analytics Local | 29/7/2020 | 17/6/2026 | IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the… |