CVE-2023-40683

HIGH

IBM OpenPages with Watson <9.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By authenticating as an OpenPages user and using non-public APIs, an attacker could exploit this vulnerability to bypass security and gain unauthorized administrative access to the application. IBM X-Force ID: 264005.

References (2)

Core 2
Core References
Patch, Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7107774

Scores

CVSS v3 8.8
EPSS 0.0002
EPSS Percentile 7.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-285
Status published
Products (2)
ibm/openpages_with_watson 9.0
ibm/openpages_with_watson 8.3 - 8.3.0.2.7
Published Jan 19, 2024
Tracked Since Feb 18, 2026