First published: Wed Feb 19 2025(Updated: )
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application establishes a session when a user logs in and uses chat, but the chat session is still left active after logout.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OpenPages | <=9.0 | |
IBM OpenPages with Watson | <=IBM OpenPages with Watson 8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49344 is considered a medium severity issue due to the potential for unauthorized access after user logout.
To fix CVE-2024-49344, you should apply the appropriate patch for your version of IBM OpenPages as specified by IBM.
CVE-2024-49344 affects IBM OpenPages with Watson versions up to 8.3 and 9.0.
The nature of CVE-2024-49344 involves the persistence of chat sessions after a user logs out, which could allow unauthorized access.
As of now, there is no publicly known exploit specifically targeting CVE-2024-49344.