First published: Mon May 25 2015(Updated: )
Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.1 | |
IBM WebSphere Portal | =8.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1921 is considered a medium severity vulnerability due to the potential for phishing attacks.
To fix CVE-2015-1921, you should upgrade to IBM WebSphere Portal versions 8.0.0.1 CF17 or 8.5.0 CF06 or later.
CVE-2015-1921 affects IBM WebSphere Portal versions 8.0.0.0, 8.0.0.1, and 8.5.0.0.
CVE-2015-1921 is an open redirect vulnerability that allows attackers to redirect users to malicious sites.
The consequences of CVE-2015-1921 include the risk of phishing attacks, leading to compromised user credentials.