IBM OpenPages with Watson Chat Session Persistence Vulnerability After Logout

Vulnerability

A vulnerability exists in IBM OpenPages with Watson versions 8.3 and 9.0, specifically when the Watson Assistant chat feature is enabled. The issue arises because the application maintains an active chat session even after the user has logged out. This could potentially lead to unauthorized access to the chat session.

Impact

Exploitation of this vulnerability could result in unauthorized access to an active chat session after a user has logged out.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
0.6
exploitability
7.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.