Open Redirect Vulnerability in IBM Process Mining Affects User Security
CVE-2025-36016

6.8MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
21 June 2025

What is CVE-2025-36016?

An open redirect vulnerability in IBM Process Mining versions 2.0.1 IF001 and 2.0.1 allows remote attackers to execute phishing attacks. By enticing users to visit a specially crafted website, attackers can exploit this flaw to manipulate the URL shown in the browser, redirecting users to malicious sites that mimic trusted environments. This exploitation could lead to the theft of sensitive information or facilitate further attacks on the victim.

Affected Version(s)

Process Mining 2.0.1 IF001, 2.0.1

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36016 : Open Redirect Vulnerability in IBM Process Mining Affects User Security