CVE-2024-49780

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
20/02/2025
Last modified:
11/03/2025

Description

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:* 8.3 (including) 8.3.0.3 (excluding)
cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:* 9.0 (including) 9.0.0.5 (excluding)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools