CVE-2025-27367

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness of fields for GRC Objects when an authenticated user sends a specially crafted payload to the server allowing for data to be saved without storing the required fields.
References
Link Resource
https://www.ibm.com/support/pages/node/7239155 Vendor Advisory Patch
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openpages_with_watson:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

14 Jul 2025, 18:00

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-08 19:15

Updated : 2025-07-14 18:00


NVD link : CVE-2025-27367

Mitre link : CVE-2025-27367

CVE.ORG link : CVE-2025-27367


JSON object : View

Products Affected

microsoft

  • windows

linux

  • linux_kernel

ibm

  • openpages_with_watson
CWE
CWE-602

Client-Side Enforcement of Server-Side Security