Metrics
Affected Vendors & Products
No advisories yet.
Solution
Remediation/Fixes A fix has been created for each affected version of the named product. Download and install the fix as soon as possible. Fixes and installation instructions are provided at the URLs listed below: Product Remediation For IBM OpenPages 9.1.1 Download URL for 9.1.1 http://ibm.com/support/pages/downloading-ibm-openpages-version-911-passport-advantage For IBM OpenPages 9.0 - Apply 9.0 FixPack 5 ( 9.0.0.5 ) - Then Apply 9.0.0.5 Interim Fix 7 ( 9.0.0.5.7 ) Download URL for 9.0.0.5 https://www.ibm.com/support/pages/ibm-openpages-90-fix-pack-5 Download URL for 9.0.0.5.7 https://www.ibm.com/support/pages/ibm-openpages-9005-interim-fix-7 For IBM OpenPages v8.0/8.1/8.2/8.3 customers, IBM recommends to upgrade to a fixed and supported version 9.0 or 9.1 of the product.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7250238 |
|
Thu, 13 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used by the user interface of OpenPages. An authenticated user is able to obtain certain information about system metadata for areas beyond what the user is intended to view. | |
| Title | IBM OpenPages Information Disclosure | |
| First Time appeared |
Ibm
Ibm openpages |
|
| Weaknesses | CWE-497 | |
| CPEs | cpe:2.3:a:ibm:openpages:9.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:openpages:9.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm openpages |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-11-12T21:03:57.566Z
Reserved: 2025-02-22T15:25:27.069Z
Link: CVE-2025-27368
Updated: 2025-11-12T20:45:36.224Z
Status : Awaiting Analysis
Published: 2025-11-12T20:15:41.480
Modified: 2025-11-14T16:42:30.503
Link: CVE-2025-27368
No data.
OpenCVE Enrichment
No data.