IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used for the administration of OpenPages. An authenticated user is able to obtain certain information about system configuration and internal state which is only intended for administrators of the system.
History

Tue, 08 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Jul 2025 19:00:00 +0000

Type Values Removed Values Added
Description IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used for the administration of OpenPages. An authenticated user is able to obtain certain information about system configuration and internal state which is only intended for administrators of the system.
Title IBM OpenPages with Watson information disclosure
First Time appeared Ibm
Ibm openpages With Watson
Weaknesses CWE-497
CPEs cpe:2.3:a:ibm:openpages_with_watson:8.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openpages_with_watson:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm openpages With Watson
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-07-08T18:43:15.373Z

Updated: 2025-07-08T19:03:39.661Z

Reserved: 2025-02-22T15:25:27.069Z

Link: CVE-2025-27369

cve-icon Vulnrichment

Updated: 2025-07-08T19:03:32.942Z

cve-icon NVD

Status : Received

Published: 2025-07-08T19:15:41.333

Modified: 2025-07-08T19:15:41.333

Link: CVE-2025-27369

cve-icon Redhat

No data.