First published: Wed Jun 20 2012(Updated: )
Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL AppScan Source | =7.0 | |
HCL AppScan Source | =8.0 | |
HCL AppScan Source | =8.0.0.1 | |
HCL AppScan Source | =8.0.0.2 | |
HCL AppScan Source | =8.5 | |
HCL AppScan Source | =8.5.0.1 | |
IBM SPSS Data Collection | =6.0 | |
IBM SPSS Data Collection | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2159 is considered a medium to high severity vulnerability due to the potential for phishing attacks.
To fix CVE-2012-2159, you should upgrade to a patched version of IBM Security AppScan Source or IBM SPSS Data Collection Developer Library.
CVE-2012-2159 affects IBM Security AppScan Source versions 7.x, 8.x before 8.6, and IBM SPSS Data Collection Developer Library versions 6.0 and 6.0.1.
CVE-2012-2159 is classified as an open redirect vulnerability.
The potential impact of CVE-2012-2159 includes unauthorized redirection of users to malicious sites, enabling phishing attacks.