Логотип exploitDog
bind:CVE-2024-49779
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-49779

Количество 3

Количество 3

nvd логотип

CVE-2024-49779

6 месяцев назад

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of authentication cookies. By modifying the CSRF token and Session Id cookie parameters using the cookies of another user, a remote attacker could exploit this vulnerability to bypass security restrictions and gain unauthorized access to the vulnerable application.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28j5-qmvp-g845

6 месяцев назад

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of authentication cookies. By modifying the CSRF token and Session Id cookie parameters using the cookies of another user, a remote attacker could exploit this vulnerability to bypass security restrictions and gain unauthorized access to the vulnerable application.

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2025-06812

6 месяцев назад

Уязвимость веб-интерфейса платформ управления рисками на предприятии IBM OpenPages и IBM OpenPages with Watson, позволяющая нарушителю осуществить CSRF-атаку

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-49779

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of authentication cookies. By modifying the CSRF token and Session Id cookie parameters using the cookies of another user, a remote attacker could exploit this vulnerability to bypass security restrictions and gain unauthorized access to the vulnerable application.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-28j5-qmvp-g845

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of authentication cookies. By modifying the CSRF token and Session Id cookie parameters using the cookies of another user, a remote attacker could exploit this vulnerability to bypass security restrictions and gain unauthorized access to the vulnerable application.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2025-06812

Уязвимость веб-интерфейса платформ управления рисками на предприятии IBM OpenPages и IBM OpenPages with Watson, позволяющая нарушителю осуществить CSRF-атаку

CVSS3: 4.3
0%
Низкий
6 месяцев назад

Уязвимостей на страницу