Open Redirect Vulnerability in IBM Security Secret Server
CVE-2019-4631
7.4HIGH
Summary
IBM Security Secret Server 10.7 is susceptible to an open redirect vulnerability that facilitates phishing attacks. A remote attacker can exploit this vulnerability by enticing a victim to visit a crafted website. By manipulating the redirect functionality, attackers can spoof URLs, leading users to malicious sites that mimic trusted ones. This exploitation may allow attackers to gather sensitive information or launch additional cyberattacks against victims.
Affected Version(s)
Security Secret Server 10.7
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved