CVE-2024-49782
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Exploitability: 3.9 / Impact: 4.2
Source: NVD
Description
IBM OpenPages with Watson 8.3 and 9.0
could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disclosed through email notifications generated by OpenPages or disrupt notification delivery.
Affected (2)
Products: Ibm: Openpages With Watson
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.3 to 8.3.0.3 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Microsoft Windows | All versions |
Related CWEs
CWE-295
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CWE-297
Improper Validation of Certificate with Host Mismatch
The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.
References (1)
Timeline
No history available yet.