📦 Openpages With Watson

by Ibm

🔍 What is Openpages With Watson?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-49781

HIGH CVSS 7.1 Feb 20, 2025

IBM OpenPages with Watson versions 8.3 and 9.0 contain an XML external entity injection (XXE) vulnerability that allows attackers to read sensitive files from the server or cause denial of service thr...

CVE-2023-40683

HIGH CVSS 8.8 Jan 19, 2024

This vulnerability in IBM OpenPages with Watson allows authenticated users to bypass authorization checks by accessing non-public APIs. Attackers can exploit this to gain unauthorized administrative a...

CVE-2021-29907

HIGH CVSS 8.8 Aug 31, 2021

This vulnerability allows authenticated users in IBM OpenPages with Watson to upload malicious files that can execute arbitrary code on the server. It affects versions 8.1 and 8.2 of the software, pot...

CVE-2025-27367

MEDIUM CVSS 5.3 Jul 8, 2025

This vulnerability allows authenticated users to bypass client-side validation in IBM OpenPages with Watson, enabling them to save GRC Objects without providing required fields. It affects versions 8....

CVE-2024-49783

MEDIUM CVSS 5.3 Jul 8, 2025

IBM OpenPages with Watson versions 8.3 and 9.0 store encrypted data with weaker-than-expected security, potentially allowing attackers to extract and decrypt sensitive information. This affects authen...

CVE-2024-49344

MEDIUM CVSS 4.3 Feb 20, 2025

IBM OpenPages with Watson versions 8.3 and 9.0 have a session management vulnerability where chat sessions remain active after user logout. This allows potential unauthorized access to chat functional...

CVE-2024-49355

MEDIUM CVSS 5.3 Feb 20, 2025

IBM OpenPages with Watson versions 8.3 and 9.0 may write improperly neutralized data to server log files when System Tracing is enabled. This could allow attackers to inject malicious content into log...

CVE-2024-49782

MEDIUM CVSS 6.8 Feb 20, 2025

This vulnerability in IBM OpenPages with Watson allows attackers to spoof mail server identity when SSL/TLS security is used. Attackers could intercept or manipulate email notifications to access sens...

CVE-2024-35117

MEDIUM CVSS 4.4 Dec 11, 2024

IBM OpenPages with Watson 9.0 may write sensitive information in clear text to system tracing log files under specific configurations. This could allow privileged users to access sensitive data they s...

CVE-2024-35151

MEDIUM CVSS 6.5 Aug 22, 2024

IBM OpenPages with Watson versions 8.3 and 9.0 contain an improper authorization vulnerability in APIs that allows authenticated users to access sensitive information they shouldn't have permission to...