PT-2025-28656 · Ibm · Ibm Openpages With Watson

Published

2025-07-08

·

Updated

2025-07-09

·

CVE-2025-27367

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: IBM OpenPages with Watson versions 8.3 through 9.0
Description: The issue is related to improper input validation. This occurs due to the bypassing of client-side validation for data types and the requiredness of fields for GRC Objects. When an authenticated user sends a specially crafted payload to the server, it allows data to be saved without storing the required fields.
Recommendations: For IBM OpenPages with Watson versions 8.3 through 9.0, consider implementing server-side validation to ensure that all required fields for GRC Objects are properly stored and validated before saving data to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-09718
CVE-2025-27367

Affected Products

Ibm Openpages With Watson