CVE-2010-2337: Input Validation
Published Jul 27, 2010
·Updated
Open redirect vulnerability in RSA Federated Identity Manager 4.0 before 4.0.25 and 4.1 before 4.1.26 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors.
Affected Software
2 affected components
RSA Federated Identity Manager=4.1
RSA Federated Identity Manager=4.0
Event History
Jul 27, 2010
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2337?
CVE-2010-2337 has a medium severity rating due to its potential for phishing attacks.
2
How do I fix CVE-2010-2337?
To fix CVE-2010-2337, upgrade RSA Federated Identity Manager to versions 4.0.25 or 4.1.26 or later.
3
What systems are affected by CVE-2010-2337?
CVE-2010-2337 affects RSA Federated Identity Manager versions 4.0 before 4.0.25 and 4.1 before 4.1.26.
4
What type of attack is possible with CVE-2010-2337?
CVE-2010-2337 allows attackers to perform open redirect attacks leading to potential phishing.
5
When was CVE-2010-2337 disclosed?
CVE-2010-2337 was disclosed in July 2010.