Remote Phishing Vulnerability in IBM Operational Decision Manager
CVE-2025-2824
7.4HIGH
What is CVE-2025-2824?
The vulnerability allows a remote attacker to exploit open redirect flaws in IBM Operational Decision Manager, creating opportunities for phishing attacks. By compelling unsuspecting users to access a specially crafted website, attackers can manipulate the URL displayed in the browser, leading users to malicious sites that mimic trusted entities. This can result in sensitive information theft and enable further malicious activities against the victim. Organizations using affected versions are strongly advised to implement the necessary security patches to protect against such exploits.
Affected Version(s)
Operational Decision Manager 8.11.0.1
Operational Decision Manager 8.11.1.0
Operational Decision Manager 8.12.0.1