IBM OpenPages with Watson 8.3 and 9.0  could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disclosed through email notifications generated by OpenPages or disrupt notification delivery.
History

Tue, 11 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm
Ibm openpages With Watson
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Weaknesses CWE-295
CPEs cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm openpages With Watson
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 20 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Feb 2025 04:00:00 +0000

Type Values Removed Values Added
Description IBM OpenPages with Watson 8.3 and 9.0  could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disclosed through email notifications generated by OpenPages or disrupt notification delivery.
Title IBM OpenPages improper certificate validation
Weaknesses CWE-297
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-02-20T16:40:23.057Z

Reserved: 2024-10-20T13:40:05.754Z

Link: CVE-2024-49782

cve-icon Vulnrichment

Updated: 2025-02-20T16:40:11.571Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-20T04:15:10.973

Modified: 2025-03-11T14:19:11.780

Link: CVE-2024-49782

cve-icon Redhat

No data.