
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability exists in IBM Planning Analytics 2.0 whereby avatars in Planning Analytics Workspace could be modified by other users without proper authorization. The vulnerability was discovered and assigned identifier CVE-2020-4648, with disclosure on August 18, 2020. The affected software is IBM Planning Analytics 2.0.x, specifically the Planning Analytics Workspace component (IBM Security).
The vulnerability has been assigned a CVSS Base score of 6.5 with a vector of (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N), indicating a moderate to high severity. The vulnerability allows unauthorized modification of user avatars within the Planning Analytics Workspace environment (IBM Security).
The vulnerability allows unauthorized users to modify avatars in Planning Analytics Workspace, potentially compromising the integrity of user identification within the system. This could lead to confusion and potential misrepresentation of user identities within the platform (IBM Security).
The vulnerability requires network access and low privilege levels to exploit, with no user interaction needed as indicated by the CVSS vector. The attack complexity is considered low, making it relatively straightforward to exploit for attackers with basic access to the system (IBM Security).
IBM has released a fix for this vulnerability in IBM Planning Analytics Local v2.0 - Planning Analytics Workspace Release 55. Users are recommended to apply this fix as soon as practical. The fix can be downloaded from IBM Fix Central. No temporary workarounds or mitigations have been identified (IBM Security).
The vulnerability was reported to IBM by security researcher Javier García, demonstrating active security community involvement in identifying and reporting security issues in IBM products (IBM Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."