First published: Wed Feb 19 2025(Updated: )
IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OpenPages | <=9.0 | |
IBM OpenPages with Watson | <=IBM OpenPages with Watson 8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49781 is considered a high severity vulnerability due to its potential for sensitive information exposure and resource consumption.
To fix CVE-2024-49781, you should apply the latest patch available for IBM OpenPages from IBM support.
CVE-2024-49781 affects IBM OpenPages versions up to and including 9.0 and IBM OpenPages with Watson version 8.3.
CVE-2024-49781 is associated with an XML External Entity (XXE) attack.
Yes, CVE-2024-49781 can be exploited remotely by attackers to gain unauthorized access to sensitive data.