PT-2025-28896 · Ibm · Ibm Openpages

Published

2025-07-09

·

Updated

2025-08-14

·

CVE-2025-2670

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IBM OpenPages version 9.0
Description: IBM OpenPages 9.0 is susceptible to the disclosure of sensitive information. This is due to insufficient security measures implemented for specific REST API endpoints associated with the workflow functionality. An authenticated user can access configuration details and internal state information related to workflows.
Recommendations: Apply appropriate security measures to the REST API endpoints related to the workflow feature.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-2670

Affected Products

Ibm Openpages