Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p8r8-86rr-6mrf

Опубликовано: 08 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

IBM OpenPages with Watson 8.3 and 9.0

could provide weaker than expected security in storage of encrypted data with AES encryption and CBC mode. If an authenticated remote attacker with access to the database or a local attacker with access to server files could extract the encrypted data values they could exploit this weaker algorithm to use additional cryptographic methods to possibly extract the encrypted data.

IBM OpenPages with Watson 8.3 and 9.0

could provide weaker than expected security in storage of encrypted data with AES encryption and CBC mode. If an authenticated remote attacker with access to the database or a local attacker with access to server files could extract the encrypted data values they could exploit this weaker algorithm to use additional cryptographic methods to possibly extract the encrypted data.

EPSS

Процентиль: 2%
0.00013
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 5.3
nvd
7 месяцев назад

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data with AES encryption and CBC mode. If an authenticated remote attacker with access to the database or a local attacker with access to server files could extract the encrypted data values they could exploit this weaker algorithm to use additional cryptographic methods to possibly extract the encrypted data.

CVSS3: 6.5
fstec
7 месяцев назад

Уязвимость платформ управления рисками на предприятии IBM OpenPages и IBM OpenPages with Watson, связанная с использованием криптографических алгоритмов, содержащих дефекты, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 2%
0.00013
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-327