Description
IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.
Published: 2024-08-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-35210 IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.
History

Fri, 23 Aug 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Ibm openpages Grc Platform
Weaknesses CWE-306
CPEs cpe:2.3:a:ibm:openpages_grc_platform:8.3:*:*:*:*:*:*:*
Vendors & Products Ibm openpages Grc Platform

Thu, 22 Aug 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 22 Aug 2024 10:30:00 +0000

Type Values Removed Values Added
Description IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.
Title IBM OpenPages information disclosure
First Time appeared Ibm
Ibm openpages With Watson
Weaknesses CWE-288
CPEs cpe:2.3:a:ibm:openpages_with_watson:8.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openpages_with_watson:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm openpages With Watson
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Openpages Grc Platform Openpages With Watson
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-08-22T12:57:30.926Z

Reserved: 2024-05-09T16:27:47.446Z

Link: CVE-2024-35151

cve-icon Vulnrichment

Updated: 2024-08-22T12:57:27.578Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-22T11:15:13.250

Modified: 2024-08-23T15:32:15.270

Link: CVE-2024-35151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses