Severity
5.3MEDIUM
EPSS
0.2%
top 57.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 1
Latest updateJan 9

Description

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used in future attacks against the system. IBM X-Force ID: 126241.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5ibm/openpages_grc_platform7.1, 7.2, 7.3+2
NVDibm/openpages_grc_platform10 versions+9

Patches

🔴Vulnerability Details

6
GHSA
debug Inefficient Regular Expression Complexity vulnerability2023-01-09
GHSA
Vercel ms Inefficient Regular Expression Complexity vulnerability2023-01-05
GHSA
GHSA-26f3-rpp2-39rf: IBM OpenPages GRC Platform 72022-05-17
GHSA
Regular Expression Denial Of Service in uri-js2018-07-24
GHSA
ReDoS in brace-expansion2018-01-29

💥Exploits & PoCs

1
Exploit-DB
Microsoft Edge Chakra JIT - Incorrect GenerateBailOut Calling Patterns2017-10-17
CVE-2017-1333 (MEDIUM CVSS 5.3) | IBM OpenPages GRC Platform 7.1 | cvebase.io