PT-2024-10414 · Ibm · Ibm Openpages With Watson

Anjana Rajan

·

Published

2024-10-04

·

Updated

2025-01-27

·

CVE-2024-37527

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM OpenPages with Watson versions 8.3 through 9.0
Description The issue is related to the web interface of IBM OpenPages and IBM OpenPages with Watson, where insufficient measures are taken to protect the web page structure. This allows a remote attacker to conduct cross-site scripting attacks, potentially gaining unauthorized access to protected information. An authenticated user can embed arbitrary JavaScript code in the Web UI, altering the intended functionality and potentially leading to credentials disclosure within a trusted session.
Recommendations For IBM OpenPages with Watson version 8.3, update to a version that includes the fix for this issue. For IBM OpenPages with Watson version 9.0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Web UI to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-00942
CVE-2024-37527

Affected Products

Ibm Openpages With Watson