CVE-2021-20526: Medium severity ibm planning analytics cloud vulnerability
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 198755.
Other sources
Node.js helmet-csp module could allow a remote attacker to bypass security restrictions, caused by a Configuration Override affecting the application's Content Security Policy (CSP). The default-src CSP policy is deleted when the package's browser sniffs for Firefox. An attacker could exploit this vulnerability to remove an application's default CSP and possibly launch a Cross-Site Scripting attack on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20526?
CVE-2021-20526 is a vulnerability in IBM Planning Analytics 2.0 that could allow a remote attacker to obtain sensitive information.
What is the severity level of CVE-2021-20526?
CVE-2021-20526 has a severity level of medium (6.5).
How does CVE-2021-20526 impact the application?
CVE-2021-20526 allows a remote attacker to bypass security restrictions in the application's Content Security Policy (CSP), potentially leading to the disclosure of sensitive information.
What is the affected software version of CVE-2021-20526?
CVE-2021-20526 affects IBM Planning Analytics 2.0.
Is there a fix available for CVE-2021-20526?
Please refer to the official IBM documentation and security advisories for available fixes and mitigation steps for CVE-2021-20526.