First published: Sun Aug 23 2015(Updated: )
Open redirect vulnerability in the web server in IBM Domino 8.5 before 8.5.3 FP6 IF9 and 9.0 before 9.0.1 FP4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via a crafted URL, aka SPR SJAR9DNGDA.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino | =8.5.0 | |
IBM Lotus Domino | =8.5.1 | |
IBM Lotus Domino | =8.5.2 | |
IBM Lotus Domino | =8.5.3 | |
IBM Lotus Domino | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2014 is classified as a medium severity vulnerability.
To fix CVE-2015-2014, upgrade IBM Domino to version 8.5.3 FP6 IF9 or 9.0.1 FP4 or later.
CVE-2015-2014 can be exploited to perform phishing attacks or cross-site scripting (XSS) attacks via crafted URLs.
CVE-2015-2014 affects IBM Domino versions 8.5.0 to 8.5.3 prior to FP6 IF9 and version 9.0 before FP4.
An open redirect vulnerability, such as CVE-2015-2014, allows attackers to redirect users to arbitrary URLs, potentially leading to malicious sites.