First published: Thu Jan 29 2015(Updated: )
Open redirect vulnerability in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the out parameter.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM TRIRIGA Application Platform | =3.2.1 | |
IBM TRIRIGA Application Platform | =3.3.2.0 | |
IBM TRIRIGA Application Platform | =3.3.2.1 | |
IBM TRIRIGA Application Platform | =3.3.2.2 | |
IBM TRIRIGA Application Platform | =3.4.0.0 | |
IBM TRIRIGA Application Platform | =3.4.0.1 | |
IBM TRIRIGA Application Platform | =3.4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8894 is classified as a medium severity vulnerability due to its potential for exploitation in phishing attacks.
To fix CVE-2014-8894, upgrade to IBM TRIRIGA Application Platform version 3.3.2.3 or 3.4.1.1 or later.
Remote authenticated users of IBM TRIRIGA Application Platform versions 3.2.1, 3.3.2.x, and 3.4.1.0 are affected by CVE-2014-8894.
CVE-2014-8894 allows attackers to perform open redirect attacks, which can facilitate phishing attempts.
Yes, CVE-2014-8894 can be exploited remotely by authenticated users to redirect others to arbitrary websites.