IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.
https://github.com/hassan-mohammed/security-findings
https://www.ibm.com/support/pages/node/7165959