Security readout for executives and security teams
Plain-English summary
IBM Planning Analytics Local 2.0 used weaker than expected cryptography. If reachable and exploitable, an unauthenticated network attacker could decrypt highly sensitive information. The issue is confidentiality-only in the CVSS record, rated medium, and the provided sources do not show active exploitation.
Executive priority
Treat as a moderate confidentiality risk for affected IBM analytics environments. Prioritize remediation if Planning Analytics Local handles financial, planning, or regulated data, or is reachable from broad internal networks.
Technical view
CVE-2020-4367 maps to IBM X-Force ID 179001. CVSS 3.0 is 5.9: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N, with official remediation noted and exploit maturity unproven. Affected product evidence is limited to IBM Planning Analytics Local 2.0. No CWE is listed.
Likely exposure
Likely exposure is organizations running IBM Planning Analytics Local 2.0, particularly where Planning Analytics services or sensitive encrypted data are network-accessible. The bundle provides no CPEs or narrower vulnerable build ranges.
Exploitation context
The sources describe potential remote confidentiality impact but high attack complexity. CISA KEV status is false in the bundle, and no cited source states active exploitation or public exploit availability.
Researcher notes
The public bundle is sparse: no CWE, no CPE, and no specific fixed version text is included. Validation should anchor on IBM advisory details and asset inventory rather than assumptions about related IBM products.
Mitigation direction
- Review IBM advisory 6214472 and apply IBM-recommended remediation.
- Upgrade or patch IBM Planning Analytics Local 2.0 according to vendor guidance.
- Restrict network access to Planning Analytics services where operationally possible.
- Identify highly sensitive data protected by affected cryptography.
- Rotate exposed secrets if investigation suggests decrypted data compromise.
Validation and detection
- Confirm whether IBM Planning Analytics Local 2.0 is deployed.
- Compare installed build and configuration against IBM advisory 6214472.
- Check vulnerability records for X-Force ID 179001 mapping.
- Review network exposure of Planning Analytics Local services.
- Look for sensitive data flows relying on affected cryptography.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2020-4367 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.9 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/AC:H/C:H/S:U/PR:N/I:N/A:N/UI:N/AV:N/RL:O/RC:C/E:U
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/AC:H/C:H/S:U/PR:N/I:N/A:N/UI:N/AV:N/RL:O/RC:C/E:U2.23.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
5.9MediumVector: CVSS:3.0/AC:H/C:H/S:U/PR:N/I:N/A:N/UI:N/AV:N/RL:O/RC:C/E:U
Source materials
- CVE List V5 sourceCVE List V5
- https://www.ibm.com/support/pages/node/6214472CVE reference · x_refsource_CONFIRM
- ibm-planning-cve20204367-info-disc (179001)CVE reference · vdb-entry, x_refsource_XF
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
