cbcvebase.
CVE-2025-27367
published 2025-07-08

CVE-2025-27367: IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness…

PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.22%
12.6th percentile
IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness of fields for GRC Objects when an authenticated user sends a specially crafted payload to the server allowing for data to be saved without storing the required fields.

Affected

5 ranges
VendorProductVersion rangeFixed in
ibmopenpages_with_watson
ibmopenpages_with_watson
ibmopenpages_with_watson>= 8.3 < 8.3.0.3.28.3.0.3.2
ibmopenpages_with_watson>= 9.0 < 9.0.0.5.39.0.0.5.3
msrccbl2_bolt_on_cbl_mariner_2.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.