CVE-2021-20477
Description
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196949.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Planning Analytics 2.0 is vulnerable to stored cross-site scripting, allowing authenticated users to inject arbitrary JavaScript that can steal credentials in a trusted session.
Vulnerability
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting (XSS) in the Web UI. An authenticated user can embed arbitrary JavaScript code, which is then executed in the context of other users' sessions. This affects IBM Planning Analytics 2.0 as per the advisory [1]. The vulnerability is classified as CVE-2021-20477 with a CVSS score of 5.4 (Medium).
Exploitation
An attacker must have a valid user account with at least low privileges to inject the malicious script. The attacker embeds JavaScript in a field or input that is later rendered in the Web UI without proper sanitization. When another user views the affected page, the script executes in their browser within the trusted session.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session. This can lead to disclosure of sensitive information, including credentials, by capturing form submissions or session tokens. The impact is limited to the scope of the user's privileges and the functionality of the Planning Analytics Workspace.
Mitigation
IBM has addressed this vulnerability in IBM Planning Analytics Local v2.0 - Planning Analytics Workspace Release 65 [1]. Users should upgrade to this or a later release. No workarounds are provided in the advisory. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 2.0
- Range: 2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/196949mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/6462331mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.