First published: Mon Sep 26 2016(Updated: )
Open redirect vulnerability in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tealeaf CX | <=8.7 | |
IBM Tealeaf CX | =8.8 | |
IBM Tealeaf CX | =9.0.0 | |
IBM Tealeaf CX | =9.0.1 | |
IBM Tealeaf CX | =9.0.1a | |
IBM Tealeaf CX | =9.0.2 | |
IBM Tealeaf CX | =9.0.2a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5977 is classified as a medium severity vulnerability due to the potential for unauthorized redirection.
To fix CVE-2016-5977, upgrade to IBM Tealeaf Customer Experience version 8.7.1.8847 FP10 or later for version 8.7, or the respective patched versions for later major releases.
Yes, CVE-2016-5977 allows for remote exploitation through crafted URLs that redirect users to malicious sites.
CVE-2016-5977 affects versions of IBM Tealeaf Customer Experience prior to 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, and others as detailed in the vulnerability description.
CVE-2016-5977 is categorized as an open redirect vulnerability, which can potentially lead to information disclosure or phishing attacks.