CVE-2025-2824: IBM Operational Decision Manager HTTP open redirect

Published Aug 1, 2025
·
Updated

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

Other sources

IBM Operational Decision Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

IBM

Affected Software

11 affected components
IBM Operational Decision Manager>=8.11.0.1<=9.5.0
IBM Operational Decision Manager<=8.11.0.1
IBM Operational Decision Manager<=8.11.1.0
IBM Operational Decision Manager<=8.12.0.1
IBM Operational Decision Manager<=9.0.0.1
IBM Operational Decision Manager<=9.5.0
IBM Operational Decision Manager=8.11.0.1
IBM Operational Decision Manager=8.11.1.0
IBM Operational Decision Manager=8.12.0.1
IBM Operational Decision Manager=9.0.0.1
IBM Operational Decision Manager=9.5.0

Remediation

Information

IBM Operational Decision Manager V8.11.0.1 Interim fix 046 is available, see download document https://www.ibm.com/support/pages/node/7238508 . IBM Operational Decision Manager V8.11.1: Interim fix 044 is available, see download document https://www.ibm.com/support/pages/node/7237139 . IBM Operational Decision Manager V8.12.0.1: Interim fix 028 is available, see download document https://www.ibm.com/support/pages/node/7236479 . IBM Operational Decision Manager V9.0.0.1: Interim fix 011 is available, see download document https://www.ibm.com/support/pages/node/7230722 .  IBM Operational Decision Manager V9.5.0.0: Interim fix 002 is available, see download document https://www.ibm.com/support/pages/node/7233740

Event History

Aug 1, 2025
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-2824?

CVE-2025-2824 is considered a high-severity vulnerability due to its potential to facilitate phishing attacks through open redirects.

2

How do I fix CVE-2025-2824?

To mitigate CVE-2025-2824, update IBM Operational Decision Manager to the latest version that addresses the vulnerability.

3

What versions are affected by CVE-2025-2824?

CVE-2025-2824 affects IBM Operational Decision Manager versions 8.11.0.1 to 9.5.0 inclusive.

4

Can CVE-2025-2824 lead to data breaches?

Yes, CVE-2025-2824 can potentially lead to data breaches by enabling attackers to successfully conduct phishing attacks.

5

Who is primarily targeted by the CVE-2025-2824 vulnerability?

CVE-2025-2824 primarily targets users of IBM Operational Decision Manager who can be tricked into visiting crafted websites.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203