PT-2024-10414 · Ibm · Ibm Openpages With Watson
Anjana Rajan
·
Published
2024-10-04
·
Updated
2025-01-27
·
CVE-2024-37527
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM OpenPages with Watson versions 8.3 through 9.0
Description
The issue is related to the web interface of IBM OpenPages and IBM OpenPages with Watson, where insufficient measures are taken to protect the web page structure. This allows a remote attacker to conduct cross-site scripting attacks, potentially gaining unauthorized access to protected information. An authenticated user can embed arbitrary JavaScript code in the Web UI, altering the intended functionality and potentially leading to credentials disclosure within a trusted session.
Recommendations
For IBM OpenPages with Watson version 8.3, update to a version that includes the fix for this issue.
For IBM OpenPages with Watson version 9.0, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the Web UI to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Openpages With Watson