CVE-2020-4882
Description
IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from user-controlled data . This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 190852.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery, allowing attackers to make requests to internal network or local file system.
Vulnerability
IBM Planning Analytics 2.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs. This allows an attacker to construct arbitrary requests that are executed by the server, potentially targeting internal network resources or the local file system. The vulnerability affects IBM Planning Analytics 2.0 as described in the security advisory [1].
Exploitation
An attacker with network access to the Planning Analytics Workspace component can craft malicious URLs that, when processed by the application, cause the server to make requests to unintended destinations. Successful exploitation requires user interaction (e.g., clicking a link) but no authentication per the CVSS vector. The attacker does not need elevated privileges.
Impact
Successful exploitation leads to low confidentiality and low integrity impacts on the system. The attacker can probe internal network services or read local files (SSRF), but the direct impact is limited as per the CVSS score of 6.1. The vulnerability cannot be used for denial of service or direct code execution.
Mitigation
IBM has released a fix in IBM Planning Analytics Local v2.0 - Planning Analytics Workspace Release 62. Users should upgrade to this version. No workarounds are available as per the advisory [1]. The vulnerability is not listed in the KEV catalog.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 2.0
- Range: 2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/190852mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/6430643mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.