VYPR
Unrated severityNVD Advisory· Published Feb 5, 2020· Updated Sep 16, 2024

CVE-2019-4613

CVE-2019-4613

Description

IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 168524.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery in Planning Analytics Workspace, allowing unauthorized actions via authenticated user.

Vulnerability

IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery (XSRF) in the Planning Analytics Workspace component. An attacker can trick an authenticated user into executing malicious actions transmitted from a user that the website trusts. The affected version is IBM Planning Analytics 2.0 [1].

Exploitation

An attacker can exploit this vulnerability by crafting a malicious link or script that, when clicked by an authenticated user, sends unauthorized requests to the Planning Analytics Workspace server. The attacker does not require authentication but relies on the victim's active session. No special network position is needed beyond the ability to deliver the malicious payload to the user [1].

Impact

Successful exploitation allows an attacker to perform unauthorized actions on behalf of the authenticated user, such as modifying settings or executing operations with the user's privileges. The CVSS score indicates a low integrity impact with no confidentiality or availability impact (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N) [1].

Mitigation

The vulnerability is fixed in IBM Planning Analytics Local v2.0 - Planning Analytics Workspace Release 48. Users should upgrade to this version. No workarounds are provided [1]. The CVE is not listed in the Known Exploited Vulnerabilities Catalog (KEV).

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.