← Back to CVE List
CVE-2025-36357NVD
Vulnerability Summary
IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences to view, read, or write arbitrary files on the system.
CVSS v3.1 Base Metrics — Score 8.0 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Ibm Planning Analytics Local >= 2.1.0 and < 2.1.15
- Ibm Planning Analytics Workspace >= 2.1.0 and < 2.1.15
- Ibm Planning Analytics Local 2.1.15
- Ibm Planning Analytics Workspace 2.1.15