Cyber Posture

CVE-2024-49779

Medium

Published: 20 February 2025

Published
20 February 2025
Modified
11 March 2025
KEV Added
Patch
CVSS Score 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score 0.0004 11.5th percentile
Risk Priority 9 60% EPSS · 20% KEV · 20% CVSS

Description

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of authentication cookies. By modifying the CSRF token and Session Id cookie parameters using the cookies of another user, a remote attacker could exploit this vulnerability to bypass security restrictions and gain unauthorized access to the vulnerable application.

Security Summary

CVE-2024-49779 is a vulnerability in IBM OpenPages with Watson versions 8.3 and 9.0 that allows a remote attacker to bypass security restrictions due to improper validation and management of authentication cookies. Specifically, the issue stems from inadequate handling of the CSRF token and Session ID cookie parameters, classified under CWE-352 (Cross-Site Request Forgery). The vulnerability has a CVSS v3.1 base score of 4.3 (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N), indicating medium severity with network accessibility, low attack complexity, no privileges required, but user interaction needed, and limited impact to integrity.

A remote attacker can exploit this vulnerability by obtaining cookies from another user and modifying the CSRF token and Session ID cookie parameters. This enables the attacker to bypass security restrictions and gain unauthorized access to the vulnerable application, though the impact is confined to low integrity effects without confidentiality or availability disruption. User interaction is required, likely in the form of a victim visiting a malicious site or clicking a crafted link that submits the tampered request.

For mitigation details, refer to the IBM security bulletin at https://www.ibm.com/support/pages/node/7183541, which provides information on patches and remediation steps for affected versions.

Details

CWE(s)
CWE-352

Affected Products

ibm
openpages with watson
8.3 — 8.3.0.3 · 9.0 — 9.0.0.5

References