PT-2025-28655 · Ibm · Ibm Openpages With Watson

CVE-2024-49784

·

Publicado

2025-07-08

·

Atualizado

2025-07-10

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IBM OpenPages with Watson versions 8.3 through 9.0
Description: The issue concerns the storage of encrypted data using AES encryption and CBC mode, which could provide weaker than expected security. An authenticated remote attacker with access to the database or a local attacker with access to server files could exploit this weakness to extract the encrypted data values and possibly use additional cryptographic methods to extract the encrypted data.
Recommendations: For IBM OpenPages with Watson versions 8.3 through 9.0, consider updating the encryption method to a stronger algorithm to mitigate the risk of exploitation. As a temporary workaround, restrict access to the encrypted data and server files to minimize the risk of unauthorized access.

Correção

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-09717
CVE-2024-49784

Produtos afetados

Ibm Openpages With Watson