CVE-2015-2014: XSS
Open redirect vulnerability in the web server in IBM Domino 8.5 before 8.5.3 FP6 IF9 and 9.0 before 9.0.1 FP4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via a crafted URL, aka SPR SJAR9DNGDA.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2014?
CVE-2015-2014 is classified as a medium severity vulnerability.
How do I fix CVE-2015-2014?
To fix CVE-2015-2014, upgrade IBM Domino to version 8.5.3 FP6 IF9 or 9.0.1 FP4 or later.
What types of attacks can exploit CVE-2015-2014?
CVE-2015-2014 can be exploited to perform phishing attacks or cross-site scripting (XSS) attacks via crafted URLs.
Which versions of IBM Domino are affected by CVE-2015-2014?
CVE-2015-2014 affects IBM Domino versions 8.5.0 to 8.5.3 prior to FP6 IF9 and version 9.0 before FP4.
What is an open redirect vulnerability like CVE-2015-2014?
An open redirect vulnerability, such as CVE-2015-2014, allows attackers to redirect users to arbitrary URLs, potentially leading to malicious sites.