First published: Sat Aug 02 2003(Updated: )
Novell iChain 2.2 before Support Pack 1 does not properly verify that URL redirects match the DNS name of an accelerator, which allows attackers to redirect URLs to malicious web sites.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell iChain | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0636 is considered critical due to its potential to enable phishing attacks by redirecting users to malicious sites.
To mitigate CVE-2003-0636, upgrade Novell iChain from version 2.2 to Support Pack 1 or later.
The risks of CVE-2003-0636 include exposure to phishing attacks and unauthorized redirection of user traffic.
CVE-2003-0636 affects Novell iChain version 2.2 prior to Support Pack 1.
Although CVE-2003-0636 is an older vulnerability, it remains relevant for organizations still using unsupported versions of Novell iChain.