CVE-2024-49344 (CVSS 4.3) leaves Watson Assistant chat sessions active post-logout, allowing reuse of cached credentials, while CVE-2024-49781 (CVSS 7.1) enables XML External Entity (XXE) attacks to extract hashed passwords from configuration files. Attackers could combine this with CVE-2024-49779 (CVSS 4.3), which bypasses CSRF protections by swapping session IDs and anti-CSRF tokens between accounts, enabling lateral movement across privileged roles. IBM’s continued investment in OpenPages’ security architecture, evidenced by 2024’s 38% reduction in CVSS 7.0+ vulnerabilities, demonstrates progress, but layered defenses remain essential. CVE-2024-49782 (CVSS 6.8): SSL/TLS certificate validation failures let attackers spoof mail servers, intercepting password reset links or exfiltrating sensitive reports. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Meanwhile, CVE-2024-49355 (CVSS 5.3) logs unsanitized user input when tracing is enabled, exposing session tokens and API keys in debug files. Kaaviya is a Security Editor and fellow reporter with Cyber Security News. CVE-2024-49337 (CVSS 5.4): HTML injection in workflow-triggered emails permits phishing payloads using <script> tags masked as benign object metadata. While OpenPages’ newer versions employ registry ACLs, legacy deployments remain susceptible to similar credential extraction techniques. She is covering various cyber security incidents happening in the Cyber Space.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 20 Feb 2025 14:50:17 +0000