IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used by the user interface of OpenPages. An authenticated user is able to obtain certain information about system metadata for areas beyond what the user is intended to view.
Advisories

No advisories yet.

Fixes

Solution

Remediation/Fixes A fix has been created for each affected version of the named product. Download and install the fix as soon as possible. Fixes and installation instructions are provided at the URLs listed below: Product Remediation For IBM OpenPages 9.1.1 Download URL for 9.1.1 http://ibm.com/support/pages/downloading-ibm-openpages-version-911-passport-advantage For IBM OpenPages 9.0 - Apply 9.0 FixPack 5 ( 9.0.0.5 ) - Then Apply 9.0.0.5 Interim Fix 7 ( 9.0.0.5.7 ) Download URL for 9.0.0.5 https://www.ibm.com/support/pages/ibm-openpages-90-fix-pack-5 Download URL for 9.0.0.5.7 https://www.ibm.com/support/pages/ibm-openpages-9005-interim-fix-7 For IBM OpenPages v8.0/8.1/8.2/8.3 customers, IBM recommends to upgrade to a fixed and supported version 9.0 or 9.1 of the product.


Workaround

No workaround given by the vendor.

History

Thu, 13 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
Description IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used by the user interface of OpenPages. An authenticated user is able to obtain certain information about system metadata for areas beyond what the user is intended to view.
Title IBM OpenPages Information Disclosure
First Time appeared Ibm
Ibm openpages
Weaknesses CWE-497
CPEs cpe:2.3:a:ibm:openpages:9.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openpages:9.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm openpages
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-11-12T21:03:57.566Z

Reserved: 2025-02-22T15:25:27.069Z

Link: CVE-2025-27368

cve-icon Vulnrichment

Updated: 2025-11-12T20:45:36.224Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-12T20:15:41.480

Modified: 2025-11-14T16:42:30.503

Link: CVE-2025-27368

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.