Open Redirect Vulnerability in IBM BigFix Inventory
CVE-2016-8961

6.1MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 February 2017

Summary

IBM BigFix Inventory v9 is susceptible to an open redirect vulnerability that allows remote attackers to conduct phishing attacks. By enticing users to click on a specially crafted link, attackers can manipulate the URL displayed in the browser, leading users to malicious websites that appear trustworthy. Exploiting this vulnerability could enable attackers to harvest sensitive information and launch further attacks against unsuspecting victims.

Affected Version(s)

BigFix Inventory 9.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.