CVE-2024-49782
Severity CVSS v4.0:
Pending analysis
Type:
CWE-297
Improper Validation of Certificate with Host Mismatch
Publication date:
20/02/2025
Last modified:
11/03/2025
Description
IBM OpenPages with Watson 8.3 and 9.0 <br />
<br />
<br />
<br />
could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disclosed through email notifications generated by OpenPages or disrupt notification delivery.
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:* | 8.3 (including) | 8.3.0.3 (excluding) |
| cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:* | 9.0 (including) | 9.0.0.5 (excluding) |
| cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



