cbcvebase.
CVE-2024-49779
published 2025-02-20

CVE-2024-49779: IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management…

PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.19%
9.2th percentile
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of authentication cookies. By modifying the CSRF token and Session Id cookie parameters using the cookies of another user, a remote attacker could exploit this vulnerability to bypass security restrictions and gain unauthorized access to the vulnerable application.

Affected

4 ranges
VendorProductVersion rangeFixed in
ibmopenpages_with_watson
ibmopenpages_with_watson
ibmopenpages_with_watson>= 8.3 < 8.3.0.38.3.0.3
ibmopenpages_with_watson>= 9.0 < 9.0.0.59.0.0.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.