← Voltar para CVEs
CVE-2025-2670
MEDIUM4.3
Descricao
IBM OpenPages 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points related to workflow feature of OpenPages. An authenticated user is able to obtain certain information about Workflow related configuration and internal state.
Detalhes CVE
Pontuacao CVSS v3.14.3
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado7/9/2025
Ultima modificacao8/14/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
ibm:openpages
Fraquezas (CWE)
CWE-497
Referencias
https://www.ibm.com/support/pages/node/7239153(psirt@us.ibm.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.