CVE-2025-14806: IBM Planning Analytics Information Disclosure
IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly cacheable resources.
Other sources
Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls. A DoS can occur that immediately halts the system due to the use of an unsafe function.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14806?
CVE-2025-14806 has been classified as a medium severity vulnerability.
How do I fix CVE-2025-14806?
To fix CVE-2025-14806, update IBM Planning Analytics Local to version 2.1.18 or later.
What does CVE-2025-14806 exploit?
CVE-2025-14806 exploits a flaw in the caching mechanism that can cause sensitive, user-specific responses to be served as publicly cacheable resources.
What versions of IBM Planning Analytics Local are affected by CVE-2025-14806?
IBM Planning Analytics Local versions 2.1.0 through 2.1.17 are affected by CVE-2025-14806.
Who is the vendor of CVE-2025-14806?
The vendor of CVE-2025-14806 is IBM, specifically for its Planning Analytics Local product.