CVE-2025-1112

Severity
4.3MEDIUM
EPSS
0.0%
top 86.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 9
Latest updateNov 19

Description

IBM OpenPages with Watson 8.3 and 9.0 could allow an authenticated user to obtain sensitive information that should only be available to privileged users.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDibm/openpages_with_watson8.38.3.0.3.2+1
CVEListV5ibm/openpages_with_watson8.3, 9.0+1

Patches

🔴Vulnerability Details

4
GHSA
esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript2025-11-19
GHSA
GHSA-qwf5-4p6v-8h59: IBM OpenPages with Watson 82025-07-09
CVEList
IBM OpenPages with Watson information disclosure2025-07-09
GHSA
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component2025-07-07

📋Vendor Advisories

1
Red Hat
kernel: f2fs: fix to do sanity check on sbi->total_valid_block_count2025-07-03
CVE-2025-1112 (MEDIUM CVSS 4.3) | IBM OpenPages with Watson 8.3 and 9 | cvebase.io