Information Disclosure in IBM OpenPages by Authenticated Users
CVE-2024-43176

5.4MEDIUM

Key Information:

Vendor
IBM
Status
Vendor
CVE Published:
9 January 2025

Summary

IBM OpenPages version 9.0 features a vulnerability where authenticated users may access sensitive information, including configurations intended exclusively for privileged users. This oversight could lead to unintentional exposure of critical system information, potentially compromising the integrity of data and the security posture of the environment.

Affected Version(s)

OpenPages 9.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.