First published: Wed Feb 19 2025(Updated: )
IBM OpenPages may write improperly neutralized data to server log files when the tracing is enabled per the System Tracing feature.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OpenPages with Watson | >8.3<=9.0 | |
IBM OpenPages with Watson | <=9.0 | |
IBM OpenPages with Watson | <=IBM OpenPages with Watson 8.3 | |
All of | ||
Any of | ||
IBM OpenPages with Watson | >=8.3<8.3.0.3 | |
IBM OpenPages with Watson | >=9.0<9.0.0.5 | |
Any of | ||
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-49355 is classified as medium due to the potential exposure of sensitive information in server log files.
To fix CVE-2024-49355, apply the patch provided in IBM OpenPages 9.0 Fix Pack 4.
CVE-2024-49355 affects IBM OpenPages with Watson up to version 8.3 and IBM OpenPages up to version 9.0.
CVE-2024-49355 allows improperly neutralized data, which could include sensitive information, to be written to server log files.
Yes, the tracing feature in IBM OpenPages is related to CVE-2024-49355 as it is when tracing is enabled that the vulnerability occurs.