First published: Wed Jan 08 2020(Updated: )
IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 170001.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Secret Server | <10.7.000059 | |
<=All |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-4631.
The severity of CVE-2019-4631 is high with a CVSS score of 7.4.
CVE-2019-4631 allows remote attackers to conduct phishing attacks by using an open redirect vulnerability to spoof the URL displayed to redirect users to a malicious website.
IBM Security Secret Server version 10.7 up to exclusive version 10.7.000059 is affected.
Yes, IBM has provided a fix for CVE-2019-4631. Please refer to the IBM Security Secret Server support page for more details.