CVE-2024-49344: IBM OpenPages session fixation
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages
with Watson Assistant chat feature enabled the application establishes a session when a user logs in and uses chat, but the chat session is still left active after logout.
Other sources
IBM OpenPages with Watson Assistant chat feature enabled the application establishes a session when a user logs in and uses chat, but the chat session is still left active after logout,
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49344?
CVE-2024-49344 is considered a medium severity issue due to the potential for unauthorized access after user logout.
How do I fix CVE-2024-49344?
To fix CVE-2024-49344, you should apply the appropriate patch for your version of IBM OpenPages as specified by IBM.
Which versions of IBM OpenPages are affected by CVE-2024-49344?
CVE-2024-49344 affects IBM OpenPages with Watson versions up to 8.3 and 9.0.
What is the nature of the vulnerability described in CVE-2024-49344?
The nature of CVE-2024-49344 involves the persistence of chat sessions after a user logs out, which could allow unauthorized access.
Is there a known exploit for CVE-2024-49344?
As of now, there is no publicly known exploit specifically targeting CVE-2024-49344.