Open Redirect Vulnerability in IBM Security Identity Manager
CVE-2021-29864

6.8MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
30 August 2022

Summary

IBM Security Identity Manager versions 6.0 and 6.0.2 contain a vulnerability that allows remote attackers to perform phishing attacks through open redirects. Attackers can trick victims into visiting a malicious site that appears legitimate by spoofing the URL. This exploitation can lead to the theft of sensitive information or further assaults on the user. It is crucial for users of affected versions to take preventive measures to mitigate risks associated with this vulnerability.

Affected Version(s)

Security Identity Manager 6.0.0

Security Identity Manager 6.0.2

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.