IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.ibm.com/support/pages/node/7183541 | 
                     | 
            
History
                    Fri, 15 Aug 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:ibm:openpages_with_watson:8.3:*:*:*:*:*:*:* cpe:2.3:a:ibm:openpages_with_watson:9.0:*:*:*:*:*:*:*  | 
Tue, 11 Mar 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Ibm
         Ibm openpages With Watson Linux Linux linux Kernel Microsoft Microsoft windows  | 
|
| CPEs | cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Ibm
         Ibm openpages With Watson Linux Linux linux Kernel Microsoft Microsoft windows  | 
Thu, 20 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 20 Feb 2025 12:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files. | IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files. | 
Thu, 20 Feb 2025 04:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files. | |
| Title | IBM OpenPages path traversal | |
| Weaknesses | CWE-22 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: ibm
Published: 2025-02-20T03:49:09.533Z
Updated: 2025-08-15T14:48:52.745Z
Reserved: 2024-10-20T13:40:05.753Z
Link: CVE-2024-49780
Updated: 2025-02-20T16:31:53.518Z
Status : Analyzed
Published: 2025-02-20T04:15:10.827
Modified: 2025-03-11T14:37:00.743
Link: CVE-2024-49780
No data.
ReportizFlow