{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-49783","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2024-10-20T13:40:05.754Z","datePublished":"2025-07-08T18:36:50.595Z","dateUpdated":"2025-08-24T11:21:43.323Z"},"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:openpages_with_watson:8.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:openpages_with_watson:9.0:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"OpenPages with Watson","vendor":"IBM","versions":[{"status":"affected","version":"8.3"},{"status":"affected","version":"9.0"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"IBM OpenPages with Watson 8.3 and 9.0 \n\n<span style=\"background-color: rgb(255, 255, 255);\">\n\n<span style=\"background-color: rgb(255, 255, 255);\">could provide weaker than expected security in storage of encrypted data. If an authenticated remote attacker with access to the database or a local attacker with access to server files could extract the encrypted data, they could exploit this vulnerability to use additional cryptographic methods to possibly extract the encrypted data.</span>\n\n</span>"}],"value":"IBM OpenPages with Watson 8.3 and 9.0 \n\n\n\ncould provide weaker than expected security in storage of encrypted data. If an authenticated remote attacker with access to the database or a local attacker with access to server files could extract the encrypted data, they could exploit this vulnerability to use additional cryptographic methods to possibly extract the encrypted data."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-329","description":"CWE-329 Generation of Predictable IV with CBC Mode","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2025-08-24T11:21:43.323Z"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7239145"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"For IBM OpenPages 9.0 - Apply 9.0 FixPack 3 (9.0.0.3) or later<br>Download URL for 9.0.0.3 -&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/ibm-openpages-90-fix-pack-3\">https://www.ibm.com/support/pages/ibm-openpages-90-fix-pack-3</a><a target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/ibm-openpages-90-fix-pack-3\"><br><br></a>For IBM OpenPages 8.3 - Apply 8.3 FixPack 3 (8.3.0.3) Then Apply 8.3.03 Interim Fix 1 (8.3.0.3.1)<a target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/ibm-openpages-90-fix-pack-3\"><br><br></a>Download URL for 8.3.0.3 <a target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/openpages-watson-83-fix-pack-3\">https://www.ibm.com/support/pages/openpages-watson-83-fix-pack-3</a><a target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/ibm-openpages-90-fix-pack-3\"><br></a>Download URL for 8.3.0.3.1 <a target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/support/pages/ibm-openpages-8303-interim-fix-1\">https://www.ibm.com/support/pages/ibm-openpages-8303-interim-fix-1</a><br>"}],"value":"For IBM OpenPages 9.0 - Apply 9.0 FixPack 3 (9.0.0.3) or later\nDownload URL for 9.0.0.3 -  https://www.ibm.com/support/pages/ibm-openpages-90-fix-pack-3  https://www.ibm.com/support/pages/openpages-watson-83-fix-pack-3  https://www.ibm.com/support/pages/ibm-openpages-8303-interim-fix-1"}],"source":{"discovery":"UNKNOWN"},"title":"IBM OpenPages with Watson information disclosure","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-07-08T18:52:12.782669Z","id":"CVE-2024-49783","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-07-08T18:55:29.347Z"}}]}}