Weakness in AES Encryption Implementation in IBM OpenPages by IBM
CVE-2024-49784

5.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
8 July 2025

What is CVE-2024-49784?

A vulnerability affecting IBM OpenPages with Watson versions 8.3 and 9.0 allows for potential weaknesses in the security of stored encrypted data due to the use of AES encryption paired with CBC mode. An authenticated remote attacker with database access, or a local attacker with server file access, could exploit this vulnerability to extract sensitive encrypted data. This exploitation could lead to unauthorized access to confidential information, making it essential for organizations utilizing these versions of OpenPages to assess their security posture and implement necessary mitigations.

Affected Version(s)

OpenPages with Watson 8.3, 9.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-49784 : Weakness in AES Encryption Implementation in IBM OpenPages by IBM