CVE-2025-3027: Open Redirect vulnerability in EJBCA
The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the requested file and redirects to an external page. This vulnerability could allow users to be redirected to potentially malicious external sites, which can be exploited for phishing or other social engineering attacks.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3027?
The severity of CVE-2025-3027 has not been specifically rated, but it poses a significant risk due to potential user redirection.
How do I fix CVE-2025-3027?
To fix CVE-2025-3027, ensure that the EJBCA service is updated to a version that addresses this vulnerability.
What impact does CVE-2025-3027 have on users?
CVE-2025-3027 can lead to users being redirected to external pages, potentially leading to phishing attacks.
Which software is affected by CVE-2025-3027?
CVE-2025-3027 affects the EJBCA service, version 8.0 Enterprise by PrimeKey.
Is there a patch available for CVE-2025-3027?
As of now, users should check with PrimeKey for any available patches or updates to mitigate CVE-2025-3027.