IBM OpenPages with Watson improper input validation
Published Jul 8, 2025
6.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
IBM OpenPages with Watson 8.3 and 9.0
is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness of fields for GRC Objects when an authenticated user sends a specially crafted payload to the server allowing for data to be saved without storing the required fields.
Affected products
-
- Version 8.3StatusaffectedConstraints-
- Version 9.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM | OpenPages with Watson | unaffected |
|
- ≥ 8.3 · < 8.3.0.3.2
- ≥ 9.0 · < 9.0.0.5.3
Running on/with
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
For IBM OpenPages 9.0 - Apply 9.0 FixPack 5 (9.0.0.5) - Then Apply 9.0.0.5 Interim Fix 3 (9.0.0.5.3) Download URL for 9.0.0.5 - https://www.ibm.com/support/pages/ibm-openpages-90-fix-pack-5 Download URL for 9.0.0.5.3 - https://www.ibm.com/support/pages/ibm-openpages-9005-interim-fix-3
For IBM OpenPages 8.3 - Apply 8.3 FixPack 3 (8.3.0.3) - Then Apply 8.3.0.3 Interim Fix 2 (8.3.0.3.2) Download URL for 8.3.0.3 - https://www.ibm.com/support/pages/openpages-watson-83-fix-pack-3 Download URL for 8.3.0.3.2 - https://www.ibm.com/support/pages/ibm-openpages-8303-interim-fix-2
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-20684 Advisory
- https://www.ibm.com/support/pages/node/7239155 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-20684 | Advisory | |
| https://www.ibm.com/support/pages/node/7239155 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.