CVE-2025-36262: IBM Planning Analytics Local information disclosure
IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13
could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.
Other sources
IBM Planning Analytics Local could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36262?
CVE-2025-36262 has been classified as a high severity vulnerability due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-36262?
To remediate CVE-2025-36262, it is recommended to update IBM Planning Analytics Local to version 2.1.14 or later, which addresses the input validation issue.
Who is affected by CVE-2025-36262?
The vulnerability affects users of IBM Planning Analytics Local versions 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13.
What is the impact of exploiting CVE-2025-36262?
Exploitation of CVE-2025-36262 could allow a malicious privileged user to bypass the user interface and access unauthorized sensitive data.
Is there a workaround for CVE-2025-36262?
Currently, there are no known workarounds for CVE-2025-36262; updating to a secure version is the only reliable solution.