Cyber Posture

CVE-2024-49779

Medium

Published: 20 February 2025

Published
20 February 2025
Modified
11 March 2025
KEV Added
Patch
CVSS Score 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score 0.0004 11.7th percentile
Risk Priority 9 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2024-49779 is a medium-severity CSRF (CWE-352) vulnerability in Ibm Openpages With Watson. Its CVSS base score is 4.3 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Web Session Cookie (T1550.004); ranked at the 11.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 AC-3 (Access Enforcement) and SC-23 (Session Authenticity).

Threat & Defense at a Glance

What attackers do: exploitation maps to Web Session Cookie (T1550.004) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

SC-23 requires protections for session authenticity, directly addressing improper CSRF token and session ID cookie validation to prevent unauthorized access via tampering.

prevent

AC-3 enforces approved authorizations for access, mitigating bypass of security restrictions due to flawed cookie-based access decisions.

prevent

SI-10 mandates validation of information inputs like CSRF tokens and session cookies, countering the improper validation exploited in this vulnerability.

MITRE ATT&CK Enterprise TechniquesAI

T1550.004 Web Session Cookie Lateral Movement
Adversaries can use stolen session cookies to authenticate to web applications and services.
T1606.001 Web Cookies Credential Access
Adversaries may forge web cookies that can be used to gain access to web applications or Internet services.
Why these techniques?

Directly enables use of tampered web session cookies and forging of CSRF tokens for unauthorized authenticated actions.

Confidence: MEDIUM · MITRE ATT&CK Enterprise v18.1

NVD Description

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of authentication cookies. By modifying the CSRF token and Session Id cookie parameters using the cookies…

more

of another user, a remote attacker could exploit this vulnerability to bypass security restrictions and gain unauthorized access to the vulnerable application.

Deeper analysisAI

CVE-2024-49779 is a vulnerability in IBM OpenPages with Watson versions 8.3 and 9.0 that allows a remote attacker to bypass security restrictions due to improper validation and management of authentication cookies. Specifically, the issue stems from inadequate handling of the CSRF token and Session ID cookie parameters, classified under CWE-352 (Cross-Site Request Forgery). The vulnerability has a CVSS v3.1 base score of 4.3 (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N), indicating medium severity with network accessibility, low attack complexity, no privileges required, but user interaction needed, and limited impact to integrity.

A remote attacker can exploit this vulnerability by obtaining cookies from another user and modifying the CSRF token and Session ID cookie parameters. This enables the attacker to bypass security restrictions and gain unauthorized access to the vulnerable application, though the impact is confined to low integrity effects without confidentiality or availability disruption. User interaction is required, likely in the form of a victim visiting a malicious site or clicking a crafted link that submits the tampered request.

For mitigation details, refer to the IBM security bulletin at https://www.ibm.com/support/pages/node/7183541, which provides information on patches and remediation steps for affected versions.

Details

CWE(s)

Affected Products

ibm
openpages with watson
8.3 — 8.3.0.3 · 9.0 — 9.0.0.5

CVEs Like This One

CVE-2024-49781Same product: Ibm Openpages With Watson
CVE-2024-49782Same product: Ibm Openpages With Watson
CVE-2025-13916Same product: Linux Linux Kernel
CVE-2024-41766Same product: Linux Linux Kernel
CVE-2024-54171Same product: Linux Linux Kernel
CVE-2024-41767Same product: Linux Linux Kernel
CVE-2024-41763Same product: Linux Linux Kernel
CVE-2025-36258Same product: Linux Linux Kernel
CVE-2025-13855Same product: Linux Linux Kernel
CVE-2024-7577Same product: Linux Linux Kernel

References