Open Redirection Vulnerability in IBM Emptoris Sourcing
CVE-2017-1449

5.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
31 August 2017

Summary

IBM Emptoris Sourcing versions 9.5 and 10.1.3 are exposed to a vulnerability that allows remote attackers to exploit open redirection. By tricking users into visiting a specially crafted website, attackers can manipulate the URL shown in the browser, leading users to malicious sites that mimic trusted pages. This scenario opens avenues for obtaining sensitive information or executing additional malicious activities against victims.

Affected Version(s)

Emptoris Sourcing 9.5

Emptoris Sourcing 10.0.0

Emptoris Sourcing 10.0.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.