CVE-2025-27369

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used for the administration of OpenPages. An authenticated user is able to obtain certain information about system configuration and internal state which is only intended for administrators of the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7239155 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

14 Jul 2025, 17:51

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7239155 - () https://www.ibm.com/support/pages/node/7239155 - Vendor Advisory
First Time Linux linux Kernel
Linux
Microsoft windows
Microsoft
Ibm
Ibm openpages With Watson
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:*

10 Jul 2025, 13:18

Type Values Removed Values Added
Summary
  • (es) IBM OpenPages con Watson 8.3 y 9.0 es vulnerable a la divulgación de información confidencial debido a una seguridad más débil de lo esperado en ciertos endpoints REST utilizados para la administración de OpenPages. Un usuario autenticado puede obtener información sobre la configuración y el estado interno del sistema, información que solo está disponible para los administradores.

08 Jul 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-08 19:15

Updated : 2025-07-14 17:51


NVD link : CVE-2025-27369

Mitre link : CVE-2025-27369

CVE.ORG link : CVE-2025-27369


JSON object : View

Products Affected

ibm

  • openpages_with_watson

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere