First published: Fri Oct 04 2024(Updated: )
IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OpenPages with Watson | >=8.3<=9.0 | |
IBM OpenPages with Watson | <=9.0 | |
IBM OpenPages with Watson | <=IBM OpenPages with Watson 8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37527 is classified as a cross-site scripting vulnerability that could lead to significant security risks, including credential exposure.
To remediate CVE-2024-37527, apply the latest security patches from IBM for OpenPages with Watson versions 8.3 and 9.0.
CVE-2024-37527 affects authenticated users of IBM OpenPages with Watson version 8.3 and 9.0.
CVE-2024-37527 allows an authenticated user to execute arbitrary JavaScript, leading to potential credential disclosure.
CVE-2024-37527 can be exploited by authenticated users with basic knowledge of JavaScript, making it a moderate risk.