First published: Mon Jul 17 2023(Updated: )
IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 252186.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access | =10.0.0 | |
<=10.0.X | ||
<=10.0.X |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-30433.
The severity rating of CVE-2023-30433 is medium with a value of 6.5.
A remote attacker can exploit CVE-2023-30433 by using an open redirect attack to conduct phishing attacks.
Versions 10.0 and 10.0.X of IBM Security Verify Access are affected by CVE-2023-30433.
You can find more information about CVE-2023-30433 at the following references: [link1](https://exchange.xforce.ibmcloud.com/vulnerabilities/252186) and [link2](https://www.ibm.com/support/pages/node/7012613).