CVE-2021-29852
Description
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205528.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Planning Analytics 2.0 contains a stored cross-site scripting vulnerability that lets authenticated attackers inject malicious scripts, potentially leading to credential theft.
Vulnerability
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting (XSS) in the Web UI. The vulnerability allows users with low privileges to embed arbitrary JavaScript code into the interface. This affects IBM Planning Analytics Local v2.0 prior to Planning Analytics Workspace Release 67 [1]. The code path is reachable when an authenticated user submits crafted input that is not properly sanitized.
Exploitation
An attacker with low-privileged access to the Planning Analytics Workspace can inject malicious JavaScript into the Web UI. To trigger the exploit, a victim user must interact with the crafted content (e.g., click a link or view a page) [1]. The attacker does not require any special network position beyond being an authenticated user.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session. This can lead to disclosure of credentials or other sensitive information within the trusted session [1]. The scope of impact is limited to the victim's browser session and the data accessible to that user.
Mitigation
The vulnerability is fixed in IBM Planning Analytics Local v2.0 - Planning Analytics Workspace Release 67 [1]. Users should upgrade to this release or later. No workarounds are documented in the available reference. The CVE is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: = 2.0
- Range: 2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/205528mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/6480413mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.