CVE Vulnerabilities

CVE-2024-35117

Cleartext Storage of Sensitive Information

Published: Dec 11, 2024 | Modified: Mar 10, 2025
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Openpages_with_watson Ibm 9.0 (including) 9.0.0.2 (excluding)

Potential Mitigations

References