Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20824 | IBM OpenPages 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points related to workflow feature of OpenPages. An authenticated user is able to obtain certain information about Workflow related configuration and internal state. |
Solution
For IBM OpenPages 9.0 - Apply 9.0 FixPack 5 (9.0.0.5) - Then Apply 9.0.0.5 Interim Fix 3 (9.0.0.5.3) Download URL for 9.0.0.5 - https://www.ibm.com/support/pages/ibm-openpages-90-fix-pack-5 Download URL for 9.0.0.5.3 - https://www.ibm.com/support/pages/ibm-openpages-9005-interim-fix-3
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7239153 |
|
Thu, 14 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm openpages
|
|
| CPEs | cpe:2.3:a:ibm:openpages:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm openpages
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM OpenPages 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points related to workflow feature of OpenPages. An authenticated user is able to obtain certain information about Workflow related configuration and internal state. | |
| Title | IBM OpenPages information disclosure | |
| First Time appeared |
Ibm
Ibm openpages With Watson |
|
| Weaknesses | CWE-497 | |
| CPEs | cpe:2.3:a:ibm:openpages_with_watson:9.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm openpages With Watson |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-24T11:19:24.916Z
Reserved: 2025-03-22T13:41:35.288Z
Link: CVE-2025-2670
Updated: 2025-07-09T15:59:02.854Z
Status : Analyzed
Published: 2025-07-09T15:15:24.370
Modified: 2025-08-14T18:48:18.750
Link: CVE-2025-2670
No data.
OpenCVE Enrichment
No data.
EUVD