CVE-2025-27367

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness of fields for GRC Objects when an authenticated user sends a specially crafted payload to the server allowing for data to be saved without storing the required fields.
References
Link Resource
https://www.ibm.com/support/pages/node/7239155 Vendor Advisory Patch
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

14 Jul 2025, 18:00

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7239155 - () https://www.ibm.com/support/pages/node/7239155 - Vendor Advisory, Patch
First Time Microsoft
Linux
Ibm
Microsoft windows
Ibm openpages With Watson
Linux linux Kernel

10 Jul 2025, 13:18

Type Values Removed Values Added
Summary
  • (es) IBM OpenPages con Watson 8.3 y 9.0 es vulnerable a una validación de entrada incorrecta debido a la omisión de la validación del lado del cliente para los tipos de datos y la exigencia de campos para objetos GRC cuando un usuario autenticado envía un paylad especialmente manipulado al servidor que permite guardar los datos sin almacenar los campos requeridos.

08 Jul 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-08 19:15

Updated : 2025-07-14 18:00


NVD link : CVE-2025-27367

Mitre link : CVE-2025-27367

CVE.ORG link : CVE-2025-27367


JSON object : View

Products Affected

linux

  • linux_kernel

microsoft

  • windows

ibm

  • openpages_with_watson
CWE
CWE-602

Client-Side Enforcement of Server-Side Security