{ "description" : { "description_data" : [ { "value" : "IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.", "lang" : "eng" } ] }, "data_type" : "CVE", "data_version" : "4.0", "CVE_data_meta" : { "DATE_PUBLIC" : "2020-08-18T00:00:00", "STATE" : "PUBLIC", "ASSIGNER" : "psirt@us.ibm.com", "ID" : "CVE-2020-4653" }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "value" : "Gain Access", "lang" : "eng" } ] } ] }, "data_format" : "MITRE", "affects" : { "vendor" : { "vendor_data" : [ { "vendor_name" : "IBM", "product" : { "product_data" : [ { "version" : { "version_data" : [ { "version_value" : "2.0" } ] }, "product_name" : "Planning Analytics" } ] } } ] } }, "impact" : { "cvssv3" : { "TM" : { "E" : "U", "RC" : "C", "RL" : "O" }, "BM" : { "UI" : "R", "PR" : "L", "C" : "N", "A" : "N", "I" : "H", "S" : "C", "AC" : "L", "SCORE" : "6.800", "AV" : "N" } } }, "references" : { "reference_data" : [ { "url" : "https://www.ibm.com/support/pages/node/6254788", "name" : "https://www.ibm.com/support/pages/node/6254788", "refsource" : "CONFIRM", "title" : "IBM Security Bulletin 6254788 (Planning Analytics)" }, { "title" : "X-Force Vulnerability Report", "refsource" : "XF", "name" : "ibm-planning-cve20204653-open-redirect (186082)", "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/186082" } ] } }