Open Redirect Vulnerability in IBM Security Secret Server
CVE-2019-4631

7.4HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
28 January 2020

Summary

IBM Security Secret Server 10.7 is susceptible to an open redirect vulnerability that facilitates phishing attacks. A remote attacker can exploit this vulnerability by enticing a victim to visit a crafted website. By manipulating the redirect functionality, attackers can spoof URLs, leading users to malicious sites that mimic trusted ones. This exploitation may allow attackers to gather sensitive information or launch additional cyberattacks against victims.

Affected Version(s)

Security Secret Server 10.7

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.