CVE-2015-7428: High severity ibm websphere portal vulnerability
Published Feb 29, 2016
·Updated
Open redirect vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
Affected Software
3 affected components
IBM WebSphere Portal=8.0.0.0
IBM WebSphere Portal=8.0.0.1
IBM WebSphere Portal=8.5.0.0
Event History
Feb 29, 2016
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7428?
CVE-2015-7428 has a medium severity level, indicating a moderate risk for potential exploitation.
2
How do I fix CVE-2015-7428?
To fix CVE-2015-7428, upgrade to IBM WebSphere Portal version 8.0.0.1 CF20 or 8.5.0.0 CF09 or later.
3
What are the impacts of CVE-2015-7428?
CVE-2015-7428 allows remote attackers to redirect users to malicious websites, facilitating phishing attacks.
4
Which versions of IBM WebSphere Portal are affected by CVE-2015-7428?
The affected versions include IBM WebSphere Portal 8.0.0.0, 8.0.0.1, and 8.5.0.0 before their respective fix packs.
5
Can CVE-2015-7428 be exploited without user interaction?
Yes, CVE-2015-7428 can be exploited through crafted URLs, potentially without user interaction.