First published: Fri Jan 11 2008(Updated: )
Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the nextPage parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java System Identity Manager | =6.0-sp2 | |
Sun Java System Identity Manager | =7.0 | |
Sun Java System Identity Manager | =6.0-sp1 | |
Sun Java System Identity Manager | =7.1 | |
Sun Java System Identity Manager | =6.0-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.