PT-2025-28655 · Ibm · Ibm Openpages With Watson
CVE-2024-49784
·
Publicado
2025-07-08
·
Atualizado
2025-07-10
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM OpenPages with Watson versions 8.3 through 9.0
Description:
The issue concerns the storage of encrypted data using AES encryption and CBC mode, which could provide weaker than expected security. An authenticated remote attacker with access to the database or a local attacker with access to server files could exploit this weakness to extract the encrypted data values and possibly use additional cryptographic methods to extract the encrypted data.
Recommendations:
For IBM OpenPages with Watson versions 8.3 through 9.0, consider updating the encryption method to a stronger algorithm to mitigate the risk of exploitation.
As a temporary workaround, restrict access to the encrypted data and server files to minimize the risk of unauthorized access.
Correção
Use of a Broken Cryptographic Algorithm
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Openpages With Watson