First published: Wed Feb 19 2025(Updated: )
IBM OpenPages could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disclosed through email notifications generated by OpenPages or disrupt notification delivery.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OpenPages | <=9.0 | |
IBM OpenPages with Watson | <=IBM OpenPages with Watson 8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49782 has a high severity due to the potential for remote attackers to spoof mail server identities.
To mitigate CVE-2024-49782, apply the patch available for IBM OpenPages version 9.0 or IBM OpenPages with Watson version 8.3.
The risks include exposure of sensitive information from email notifications and potential disruption of notification delivery.
CVE-2024-49782 affects IBM OpenPages up to version 9.0 and IBM OpenPages with Watson up to version 8.3.
Yes, CVE-2024-49782 can be exploited remotely by attackers to spoof email identities.