CVE-2023-38738

MEDIUM

IBM OpenPages with Watson <9.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPages is using Native authentication an attacker with access to the OpenPages database could through a series of specially crafted steps could exploit this weakness and gain unauthorized access to other OpenPages accounts. IBM X-Force ID: 262594.

Scores

CVSS v3 6.8
EPSS 0.0006
EPSS Percentile 17.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-257
Status published
Products (2)
ibm/openpages_with_watson 9.0
ibm/openpages_with_watson 8.3 - 8.3.0.2.7
Published Jan 19, 2024
Tracked Since Feb 18, 2026