First published: Tue Jul 27 2010(Updated: )
Open redirect vulnerability in RSA Federated Identity Manager 4.0 before 4.0.25 and 4.1 before 4.1.26 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Federated Identity Manager | =4.1 | |
RSA Federated Identity Manager | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2337 has a medium severity rating due to its potential for phishing attacks.
To fix CVE-2010-2337, upgrade RSA Federated Identity Manager to versions 4.0.25 or 4.1.26 or later.
CVE-2010-2337 affects RSA Federated Identity Manager versions 4.0 before 4.0.25 and 4.1 before 4.1.26.
CVE-2010-2337 allows attackers to perform open redirect attacks leading to potential phishing.
CVE-2010-2337 was disclosed in July 2010.