First published: Wed Oct 02 2019(Updated: )
IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 165660.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Directory Server | =6.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4538 is a vulnerability in IBM Security Directory Server 6.4.0 that could allow a remote attacker to conduct phishing attacks using an open redirect attack.
CVE-2019-4538 works by persuading a victim to visit a specially-crafted website, allowing a remote attacker to spoof the URL displayed and redirect the user to a malicious site.
The severity of CVE-2019-4538 is rated as high with a CVSS score of 8.2 out of 10.
IBM Security Directory Server version 6.4.0 is affected by CVE-2019-4538.
Yes, IBM has provided a fix for the vulnerability. Please refer to the following IBM support page for more information: <https://www.ibm.com/support/pages/node/1077045>.