CVE-2021-29851
Description
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 205527.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Planning Analytics 2.0 discloses sensitive information in browser stack traces, aiding reconnaissance for further attacks.
Vulnerability
IBM Planning Analytics 2.0 (including Planning Analytics Workspace) returns detailed stack trace information in the browser when an error occurs. This information leakage affects versions prior to Planning Analytics Local v2.0 – Planning Analytics Workspace Release 67. The vulnerability exists because the application does not properly sanitize or suppress error output, causing stack traces to be transmitted to the client [1].
Exploitation
An unauthenticated attacker with network access can trigger an error condition in the application (for example by sending a malformed request) and capture the resulting stack trace. No special privileges or user interaction beyond normal browsing is required [1]. The stack trace is returned directly in the HTTP response.
Impact
Successful exploitation allows a remote attacker to obtain sensitive information about the application's internal structure, file paths, and potentially other technical details disclosed in the stack trace. This information can be used to craft more targeted attacks. The CVSS v3.0 base score for this information disclosure is 4.3 (medium severity) [1].
Mitigation
IBM has addressed this vulnerability in IBM Planning Analytics Local v2.0 – Planning Analytics Workspace Release 67, which should be applied to affected systems. For details on obtaining the fix, refer to the IBM security bulletin [1]. No workaround is described in the available references.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: =2.0
- Range: 2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/205527mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/6480413mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.