CVE-2023-38738: IBM OpenPages with Watson information disclosure
IBM OpenPages could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPages is using Native authentication an attacker with access to the OpenPages database could through a series of specially crafted steps could exploit this weakness and gain unauthorized access to other OpenPages accounts.
Other sources
IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPages is using Native authentication an attacker with access to the OpenPages database could through a series of specially crafted steps could exploit this weakness and gain unauthorized access to other OpenPages accounts. IBM X-Force ID: 262594.
— NVD
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38738?
The severity of CVE-2023-38738 is classified as a medium risk due to potential unauthorized access in specific environments.
How do I fix CVE-2023-38738?
To fix CVE-2023-38738, apply the latest fix pack updates available for IBM OpenPages with Watson version 8.3 or 9.0.
What systems are affected by CVE-2023-38738?
CVE-2023-38738 affects IBM OpenPages with Watson versions up to and including 9.0 and 8.3.
What authentication mechanism is implicated in CVE-2023-38738?
CVE-2023-38738 is specifically related to vulnerabilities in the Native authentication method used in OpenPages.
Can an attacker exploit CVE-2023-38738 remotely?
Yes, an attacker with access to the OpenPages database can potentially exploit CVE-2023-38738 through crafted steps.