CVE-2025-2824: IBM Operational Decision Manager HTTP open redirect
IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Other sources
IBM Operational Decision Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2824?
CVE-2025-2824 is considered a high-severity vulnerability due to its potential to facilitate phishing attacks through open redirects.
How do I fix CVE-2025-2824?
To mitigate CVE-2025-2824, update IBM Operational Decision Manager to the latest version that addresses the vulnerability.
What versions are affected by CVE-2025-2824?
CVE-2025-2824 affects IBM Operational Decision Manager versions 8.11.0.1 to 9.5.0 inclusive.
Can CVE-2025-2824 lead to data breaches?
Yes, CVE-2025-2824 can potentially lead to data breaches by enabling attackers to successfully conduct phishing attacks.
Who is primarily targeted by the CVE-2025-2824 vulnerability?
CVE-2025-2824 primarily targets users of IBM Operational Decision Manager who can be tricked into visiting crafted websites.