IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used by the user interface of OpenPages. An authenticated user is able to obtain certain information about system metadata for areas beyond what the user is intended to view.
History

Tue, 18 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:openpages:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openpages:9.1.0:*:*:*:*:*:*:*

Thu, 13 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
Description IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used by the user interface of OpenPages. An authenticated user is able to obtain certain information about system metadata for areas beyond what the user is intended to view.
Title IBM OpenPages Information Disclosure
First Time appeared Ibm
Ibm openpages
Weaknesses CWE-497
CPEs cpe:2.3:a:ibm:openpages:9.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openpages:9.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm openpages
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-11-12T19:11:10.308Z

Updated: 2025-11-12T21:03:57.566Z

Reserved: 2025-02-22T15:25:27.069Z

Link: CVE-2025-27368

cve-icon Vulnrichment

Updated: 2025-11-12T20:45:36.224Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-12T20:15:41.480

Modified: 2025-11-18T19:12:32.107

Link: CVE-2025-27368

cve-icon Redhat

No data.