CVE-2024-49782: IBM OpenPages improper certificate validation
IBM OpenPages could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disclosed through email notifications generated by OpenPages or disrupt notification delivery.
Other sources
IBM OpenPages with Watson 8.3 and 9.0
could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disclosed through email notifications generated by OpenPages or disrupt notification delivery.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49782?
CVE-2024-49782 has a high severity due to the potential for remote attackers to spoof mail server identities.
How do I fix CVE-2024-49782?
To mitigate CVE-2024-49782, apply the patch available for IBM OpenPages version 9.0 or IBM OpenPages with Watson version 8.3.
What are the risks associated with CVE-2024-49782?
The risks include exposure of sensitive information from email notifications and potential disruption of notification delivery.
Which versions of IBM OpenPages are affected by CVE-2024-49782?
CVE-2024-49782 affects IBM OpenPages up to version 9.0 and IBM OpenPages with Watson up to version 8.3.
Can CVE-2024-49782 be exploited remotely?
Yes, CVE-2024-49782 can be exploited remotely by attackers to spoof email identities.