4.3
CVE-2024-43196
- EPSS 0.1%
- Veröffentlicht 20.02.2025 04:15:09
- Zuletzt bearbeitet 11.03.2025 14:57:13
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM OpenPages data manipulation
IBM OpenPages with Watson 8.3 and 9.0 application could allow an authenticated user to manipulate data in the Questionnaires application allowing the user to spoof other users' responses.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Openpages With Watson Version >= 8.3 < 8.3.0.3
Ibm ≫ Openpages With Watson Version >= 9.0 < 9.0.0.5
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.284 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-296 Improper Following of a Certificate's Chain of Trust
The product does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate, resulting in incorrect trust of any resource that is associated with that certificate.