Open Redirect Vulnerability in IBM Cognos Analytics
CVE-2024-45082
5.2MEDIUM
Summary
An open redirect vulnerability has been identified in IBM Cognos Analytics versions 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3. This flaw allows a remote attacker to execute phishing attacks by redirecting users to a malicious website. By luring a victim to click on a crafted link, an attacker can exploit this vulnerability to manipulate the URL displayed in the browser, presenting a legitimate appearance that misdirects users to untrustworthy sites. Organizations using affected versions should take immediate action to mitigate the risks associated with this vulnerability.
References
CVSS V3.1
Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published