Rewterz
Rewterz Threat Alert – AZORult – IOCs
June 1, 2020
Rewterz
Rewterz Threat Alert – Trickbot Updated with Nworm
June 1, 2020

Rewterz Threat Advisory – CVE-2020-4306 – IBM Planning Analytics Local Cross-Site Scripting Vulnerability

Severity

Low

Analysis Summary

IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Impact

Cross-site scripting

Affected Vendors

IBM

Affected Products

  • IBM Planning Analytics Local 2.0.0
  • IBM Planning Analytics Local 2.0.9

Remediation

Refer to IBM Security Bulletin 6213263 for upgraded patch.

https://www.ibm.com/support/pages/node/6213263