Openpages Grc Platform
Vendor:
First CVE: Jun 27, 2014 · Active for 12 years
22
Total CVEs
More Total CVEs than 95% of tracked products
3.1
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
5.1
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openpages Grc Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2014
12 years ago
Most Recent CVE
Sep 10, 2024
686 days ago
CVE Severity & Scoring
Openpages Grc Platform22 CVEs
14%
82%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local2 (9.1%)
Network12 (54.5%)
Unknown8 (36.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (63.6%)
High0 (0.0%)
Unknown8 (36.4%)
User Interaction
None8 (36.4%)
Unknown8 (36.4%)
Required6 (27.3%)
Privileges Required
Low11 (50.0%)
High0 (0.0%)
None3 (13.6%)
Unknown8 (36.4%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1300HIGH IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted fro | Nov 1, 2017 | 8.8 | 22 | NO | NO |
CVE-2016-3048MEDIUM IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t | Nov 1, 2017 | 5.4 | 21 | NO | NO |
CVE-2011-1381MEDIUM Unspecified vulnerability in IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to bypass intended access restrictions via unknown vectors. | Jun 27, 2014 | 6.4 | 21 | NO | NO |
CVE-2024-35151MEDIUM IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs. | Aug 22, 2024 | 6.5 | 20 | NO | NO |
CVE-2017-1679MEDIUM IBM OpenPages GRC Platform 7.2, 7.3, 7.4, and 8.0 could allow an attacker to obtain sensitive information from error log files. IBM X-Force ID: 134001. | Sep 10, 2018 | 5.5 | 20 | NO | NO |
CVE-2016-3049MEDIUM IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim | Oct 24, 2017 | 5.4 | 19 | NO | NO |
CVE-2015-0145MEDIUM Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticat | Oct 3, 2015 | 6.8 | 19 | NO | NO |
CVE-2014-3011MEDIUM IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified vectors. | Jun 27, 2014 | 5.0 | 19 | NO | NO |
CVE-2017-1333MEDIUM IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used in future attacks against the s | Nov 1, 2017 | 5.3 | 16 | NO | NO |
CVE-2017-1290MEDIUM IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t | Nov 1, 2017 | 5.4 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Openpages Grc Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.3 | 1 | 6.5 | 0.4% | 0 | 0 |
| 8.0.0.0 | 1 | 5.5 | 0.4% | 0 | 0 |
| 7.4.0.0 | 1 | 5.5 | 0.4% | 0 | 0 |
| 7.3.0.0 | 8 | 5.5 | 0.8% | 0 | 0 |
| 7.3 | 1 | 5.4 | 0.9% | 0 | 0 |
| 7.2.0.4 | 6 | 5.9 | 0.9% | 0 | 0 |
| 7.2.0.3 | 6 | 5.9 | 0.9% | 0 | 0 |
| 7.2.0.2 | 6 | 5.9 | 0.9% | 0 | 0 |
| 7.2.0.1 | 6 | 5.9 | 0.9% | 0 | 0 |
| 7.2.0.0 | 7 | 5.9 | 0.8% | 0 | 0 |
| 7.2 | 1 | 5.4 | 0.9% | 0 | 0 |
| 7.1.0.3 | 6 | 5.9 | 0.9% | 0 | 0 |
| 7.1.0.2 | 6 | 5.9 | 0.9% | 0 | 0 |
| 7.1.0.1 | 7 | 5.9 | 0.9% | 0 | 0 |
| 7.1.0.0 | 13 | 5.1 | 0.9% | 0 | 0 |
| 7.1 | 1 | 5.4 | 0.9% | 0 | 0 |
| 7.0.0.4 | 1 | 5.4 | 0.7% | 0 | 0 |
| 7.0.0.3 | 1 | 5.4 | 0.7% | 0 | 0 |
| 7.0.0.2 | 1 | 5.4 | 0.7% | 0 | 0 |
| 7.0.0.1 | 1 | 5.4 | 0.7% | 0 | 0 |