CVE-2025-33005

IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7235182 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:planning_analytics_local:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:planning_analytics_local:2.1.0:*:*:*:*:*:*:*

History

09 Jun 2025, 18:07

Type Values Removed Values Added
Summary
  • (es) IBM Planning Analytics Local 2.0 y 2.1 no invalida la sesión después de un cierre de sesión, lo que podría permitir que un usuario autenticado se haga pasar por otro usuario en el sistema.
First Time Ibm planning Analytics Local
Ibm
References () https://www.ibm.com/support/pages/node/7235182 - () https://www.ibm.com/support/pages/node/7235182 - Vendor Advisory
CPE cpe:2.3:a:ibm:planning_analytics_local:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:planning_analytics_local:2.1.0:*:*:*:*:*:*:*

01 Jun 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-01 12:15

Updated : 2025-06-09 18:07


NVD link : CVE-2025-33005

Mitre link : CVE-2025-33005

CVE.ORG link : CVE-2025-33005


JSON object : View

Products Affected

ibm

  • planning_analytics_local
CWE
CWE-613

Insufficient Session Expiration