4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description
IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used by the user interface of OpenPages. An authenticated user is able to obtain certain information about system metadata for areas beyond what the user is intended to view.
Basic Information
ID
CVE-2025-27368
Source
ibm
Published
Nov 12, 2025 at 19:11
Modified
Nov 12, 2025 at 21:03
Affected Product
Vendor
IBM
Product
OpenPages
Version
9.0
Affected Versions
IBM OpenPages 9.0
IBM OpenPages 9.1
IBM OpenPages 9.1