PT-2026-66556 · Ibm · Ibm Planning Analytics Local
CVE-2026-10545
·
Published
2026-07-30
·
Updated
2026-08-12
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Planning Analytics Local versions 2.1.0 through 2.1.21
Description
An open redirect exists that allows an attacker to redirect users to arbitrary external websites using a crafted URL. When this occurs within Single Sign-On (SSO) authentication flows, it may lead to the exposure of session tokens, potentially enabling attackers to hijack user sessions.
Recommendations
Update IBM Planning Analytics Local to a version later than 2.1.21.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Planning Analytics Local