PT-2025-28655 · Ibm · Ibm Openpages With Watson
Published
2025-07-08
·
Updated
2025-07-10
·
CVE-2024-49784
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM OpenPages with Watson versions 8.3 through 9.0
Description:
The issue concerns the storage of encrypted data using AES encryption and CBC mode, which could provide weaker than expected security. An authenticated remote attacker with access to the database or a local attacker with access to server files could exploit this weakness to extract the encrypted data values and possibly use additional cryptographic methods to extract the encrypted data.
Recommendations:
For IBM OpenPages with Watson versions 8.3 through 9.0, consider updating the encryption method to a stronger algorithm to mitigate the risk of exploitation.
As a temporary workaround, restrict access to the encrypted data and server files to minimize the risk of unauthorized access.
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Openpages With Watson