PT-2025-7430 · Ibm · Ibm Openpages With Watson

Published

2025-02-19

·

Updated

2025-03-11

·

CVE-2024-49780

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM OpenPages with Watson versions 8.3 through 9.0
Description The issue allows a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files.
Recommendations For versions 8.3 and 9.0, consider disabling the Import Configuration feature until a patch is available to prevent directory traversal attacks. Restrict access to the Import Configuration module to minimize the risk of exploitation. Avoid using the file name parameter in the affected Import Configuration endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06818
CVE-2024-49780

Affected Products

Ibm Openpages With Watson