CVE-2020-4649: Infoleak
IBM Planning Analytics could expose data to non-privleged users by not invalidating TM1Web user sessions.
Other sources
IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions. IBM X-Force ID: 186022.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-4649.
What is the severity level of CVE-2020-4649?
CVE-2020-4649 has a severity level of medium.
How does CVE-2020-4649 impact IBM Planning Analytics?
CVE-2020-4649 could expose data to non-privileged users by not invalidating TM1Web user sessions in IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57.
Which software versions are affected by CVE-2020-4649?
IBM Planning Analytics Local 2.0.9.2 is affected by CVE-2020-4649.
How can CVE-2020-4649 be fixed?
To fix CVE-2020-4649, update IBM Planning Analytics Local to a version that includes the necessary security patches.