is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness of fields for GRC Objects when an authenticated user sends a specially crafted payload to the server allowing for data to be saved without storing the required fields.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
For IBM OpenPages 9.0 - Apply 9.0 FixPack 5 (9.0.0.5) - Then Apply 9.0.0.5 Interim Fix 3 (9.0.0.5.3) Download URL for 9.0.0.5 - https://www.ibm.com/support/pages/ibm-openpages-90-fix-pack-5 Download URL for 9.0.0.5.3 - https://www.ibm.com/support/pages/ibm-openpages-9005-interim-fix-3 For IBM OpenPages 8.3 - Apply 8.3 FixPack 3 (8.3.0.3) - Then Apply 8.3.0.3 Interim Fix 2 (8.3.0.3.2) Download URL for 8.3.0.3 - https://www.ibm.com/support/pages/openpages-watson-83-fix-pack-3 Download URL for 8.3.0.3.2 - https://www.ibm.com/support/pages/ibm-openpages-8303-interim-fix-2
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20684 | IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness of fields for GRC Objects when an authenticated user sends a specially crafted payload to the server allowing for data to be saved without storing the required fields. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7239155 |
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel Microsoft Microsoft windows |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness of fields for GRC Objects when an authenticated user sends a specially crafted payload to the server allowing for data to be saved without storing the required fields. | |
| Title | IBM OpenPages with Watson improper input validation | |
| First Time appeared |
Ibm
Ibm openpages With Watson |
|
| Weaknesses | CWE-602 | |
| CPEs | cpe:2.3:a:ibm:openpages_with_watson:8.3:*:*:*:*:*:*:* cpe:2.3:a:ibm:openpages_with_watson:9.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm openpages With Watson |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-24T11:23:31.695Z
Reserved: 2025-02-22T15:25:27.069Z
Link: CVE-2025-27367
Updated: 2025-07-08T19:06:07.343Z
Status : Analyzed
Published: 2025-07-08T19:15:40.150
Modified: 2025-07-14T18:00:43.950
Link: CVE-2025-27367
No data.
OpenCVE Enrichment
No data.
EUVD