Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5m9f-w8v4-rvgm

Опубликовано: 19 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By authenticating as an OpenPages user and using non-public APIs, an attacker could exploit this vulnerability to bypass security and gain unauthorized administrative access to the application. IBM X-Force ID: 264005.

IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By authenticating as an OpenPages user and using non-public APIs, an attacker could exploit this vulnerability to bypass security and gain unauthorized administrative access to the application. IBM X-Force ID: 264005.

EPSS

Процентиль: 6%
0.00024
Низкий

8.8 High

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By authenticating as an OpenPages user and using non-public APIs, an attacker could exploit this vulnerability to bypass security and gain unauthorized administrative access to the application. IBM X-Force ID: 264005.

EPSS

Процентиль: 6%
0.00024
Низкий

8.8 High

CVSS3

Дефекты

CWE-285