CVE-2017-1156: High severity ibm websphere portal vulnerability
IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force. ID: 122592
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1156?
CVE-2017-1156 has been classified as a medium severity vulnerability.
How do I fix CVE-2017-1156?
To mitigate CVE-2017-1156, upgrade IBM WebSphere Portal to version 9.0.5.5 or 8.5.5.12 or later.
What impact does CVE-2017-1156 have on users?
CVE-2017-1156 can lead to phishing attacks by redirecting users to malicious sites.
Which versions of IBM WebSphere Portal are affected by CVE-2017-1156?
CVE-2017-1156 affects IBM WebSphere Portal versions 8.5 and 9.0.
Can CVE-2017-1156 be exploited remotely?
Yes, CVE-2017-1156 can be exploited remotely by an attacker to conduct phishing attacks.