IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used by the user interface of OpenPages. An authenticated user is able to obtain certain information about system metadata for areas beyond what the user is intended to view.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7250238 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Nov 2025, 19:12
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:ibm:openpages:9.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:openpages:9.0.0:*:*:*:*:*:*:* |
|
| References | () https://www.ibm.com/support/pages/node/7250238 - Vendor Advisory | |
| First Time |
Ibm openpages
Ibm |
12 Nov 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-12 20:15
Updated : 2025-11-18 19:12
NVD link : CVE-2025-27368
Mitre link : CVE-2025-27368
CVE.ORG link : CVE-2025-27368
JSON object : View
Products Affected
ibm
- openpages
CWE
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
