CVE-2024-49779
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 20, 2025
CWE ID 352
Summary
CVE-2024-49779 is a vulnerability affecting IBM OpenPages with Watson 8.3 and 9.0. An attacker can exploit this issue by manipulating authentication cookies, specifically the CSRF token and Session Id cookie parameters. By using the cookies of another user, a remote attacker could bypass security restrictions and unauthorizedly access the vulnerable application. This vulnerability stems from improper validation and management of these cookies.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- IBM Corporation