VYPR
Unrated severityNVD Advisory· Published Sep 1, 2021· Updated Sep 17, 2024

CVE-2021-29851

CVE-2021-29851

Description

IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 205527.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Planning Analytics 2.0 discloses sensitive information in browser stack traces, aiding reconnaissance for further attacks.

Vulnerability

IBM Planning Analytics 2.0 (including Planning Analytics Workspace) returns detailed stack trace information in the browser when an error occurs. This information leakage affects versions prior to Planning Analytics Local v2.0 – Planning Analytics Workspace Release 67. The vulnerability exists because the application does not properly sanitize or suppress error output, causing stack traces to be transmitted to the client [1].

Exploitation

An unauthenticated attacker with network access can trigger an error condition in the application (for example by sending a malformed request) and capture the resulting stack trace. No special privileges or user interaction beyond normal browsing is required [1]. The stack trace is returned directly in the HTTP response.

Impact

Successful exploitation allows a remote attacker to obtain sensitive information about the application's internal structure, file paths, and potentially other technical details disclosed in the stack trace. This information can be used to craft more targeted attacks. The CVSS v3.0 base score for this information disclosure is 4.3 (medium severity) [1].

Mitigation

IBM has addressed this vulnerability in IBM Planning Analytics Local v2.0 – Planning Analytics Workspace Release 67, which should be applied to affected systems. For details on obtaining the fix, refer to the IBM security bulletin [1]. No workaround is described in the available references.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.