IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used by the user interface of OpenPages. An authenticated user is able to obtain certain information about system metadata for areas beyond what the user is intended to view.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7250238 |
|
History
Tue, 18 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:openpages:9.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:openpages:9.1.0:*:*:*:*:*:*:* |
Thu, 13 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used by the user interface of OpenPages. An authenticated user is able to obtain certain information about system metadata for areas beyond what the user is intended to view. | |
| Title | IBM OpenPages Information Disclosure | |
| First Time appeared |
Ibm
Ibm openpages |
|
| Weaknesses | CWE-497 | |
| CPEs | cpe:2.3:a:ibm:openpages:9.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:openpages:9.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm openpages |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-11-12T19:11:10.308Z
Updated: 2025-11-12T21:03:57.566Z
Reserved: 2025-02-22T15:25:27.069Z
Link: CVE-2025-27368
Updated: 2025-11-12T20:45:36.224Z
Status : Analyzed
Published: 2025-11-12T20:15:41.480
Modified: 2025-11-18T19:12:32.107
Link: CVE-2025-27368
No data.