CVE-2024-35117: IBM OpenPages with Watson information disclosure
IBM OpenPages may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user.
Other sources
IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35117?
CVE-2024-35117 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2024-35117?
To fix CVE-2024-35117, apply the recommended patch from IBM for OpenPages version 9.0.
Who is affected by CVE-2024-35117?
CVE-2024-35117 affects IBM OpenPages with Watson version 9.0 when specific configurations are applied.
What information is exposed in CVE-2024-35117?
CVE-2024-35117 may expose sensitive information that is written in clear text in system tracing log files.
Can a privileged user exploit CVE-2024-35117?
Yes, a privileged user may obtain sensitive information due to the insecure logging mechanism described in CVE-2024-35117.