First published: Mon Sep 09 2024(Updated: )
IBM OpenPages 8.3 and 9.0 potentially exposes information about client-side source code through use of JavaScript source maps to unauthorized users.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OpenPages with Watson | <=9.0 | |
IBM OpenPages with Watson | <=IBM OpenPages with Watson 8.3 | |
IBM OpenPages | >=8.3<8.3.0.2 | |
IBM OpenPages with Watson | >=9.0<9.0.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27257 is considered a medium severity vulnerability due to the potential exposure of sensitive client-side source code.
To fix CVE-2024-27257, apply the relevant patches provided by IBM for OpenPages 8.3 and 9.0.
CVE-2024-27257 affects IBM OpenPages versions up to and including 9.0 and IBM OpenPages with Watson up to and including 8.3.
CVE-2024-27257 potentially exposes client-side source code information through JavaScript source maps.
No, CVE-2024-27257 can still pose a risk as it may expose information to unauthorized users regardless of user authentication.