CVE-2019-4613
Description
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 168524.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery in Planning Analytics Workspace, allowing unauthorized actions via authenticated user.
Vulnerability
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery (XSRF) in the Planning Analytics Workspace component. An attacker can trick an authenticated user into executing malicious actions transmitted from a user that the website trusts. The affected version is IBM Planning Analytics 2.0 [1].
Exploitation
An attacker can exploit this vulnerability by crafting a malicious link or script that, when clicked by an authenticated user, sends unauthorized requests to the Planning Analytics Workspace server. The attacker does not require authentication but relies on the victim's active session. No special network position is needed beyond the ability to deliver the malicious payload to the user [1].
Impact
Successful exploitation allows an attacker to perform unauthorized actions on behalf of the authenticated user, such as modifying settings or executing operations with the user's privileges. The CVSS score indicates a low integrity impact with no confidentiality or availability impact (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N) [1].
Mitigation
The vulnerability is fixed in IBM Planning Analytics Local v2.0 - Planning Analytics Workspace Release 48. Users should upgrade to this version. No workarounds are provided [1]. The CVE is not listed in the Known Exploited Vulnerabilities Catalog (KEV).
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: =2.0
- Range: 2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/168524mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/1172860mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.