CVE-2024-27257

CWE-5403 documents3 sources
Severity
4.3MEDIUM
EPSS
0.1%
top 68.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10

Description

IBM OpenPages 8.3 and 9.0 potentially exposes information about client-side source code through use of JavaScript source maps to unauthorized users.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

NVDibm/openpages_with_watson9.09.0.0.3
NVDibm/openpages_grc_platform8.38.3.0.2
CVEListV5ibm/openpages8.3, 9.0

🔴Vulnerability Details

2
CVEList
IBM OpenPages information disclosure2024-09-10
GHSA
GHSA-8j7x-j8g8-g329: IBM OpenPages 82024-09-10
CVE-2024-27257 (MEDIUM CVSS 4.3) | IBM OpenPages 8.3 and 9.0 potential | cvebase.io