CVE-2024-27257: IBM OpenPages information disclosure
IBM OpenPages 8.3 and 9.0 potentially exposes information about client-side source code through use of JavaScript source maps to unauthorized users.
Other sources
IBM OpenPages potentially exposes information about client-side source code through use of JavaScript source maps to unauthorized users.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27257?
CVE-2024-27257 is considered a medium severity vulnerability due to the potential exposure of sensitive client-side source code.
How do I fix CVE-2024-27257?
To fix CVE-2024-27257, apply the relevant patches provided by IBM for OpenPages 8.3 and 9.0.
What versions of IBM OpenPages are affected by CVE-2024-27257?
CVE-2024-27257 affects IBM OpenPages versions up to and including 9.0 and IBM OpenPages with Watson up to and including 8.3.
What type of information does CVE-2024-27257 expose?
CVE-2024-27257 potentially exposes client-side source code information through JavaScript source maps.
Is user authentication sufficient to prevent CVE-2024-27257?
No, CVE-2024-27257 can still pose a risk as it may expose information to unauthorized users regardless of user authentication.