Weakness in AES Encryption Implementation in IBM OpenPages by IBM
CVE-2024-49784
5.3MEDIUM
What is CVE-2024-49784?
A vulnerability affecting IBM OpenPages with Watson versions 8.3 and 9.0 allows for potential weaknesses in the security of stored encrypted data due to the use of AES encryption paired with CBC mode. An authenticated remote attacker with database access, or a local attacker with server file access, could exploit this vulnerability to extract sensitive encrypted data. This exploitation could lead to unauthorized access to confidential information, making it essential for organizations utilizing these versions of OpenPages to assess their security posture and implement necessary mitigations.
Affected Version(s)
OpenPages with Watson 8.3, 9.0