{"api_version":"1","generated_at":"2026-07-23T11:48:08+00:00","cve":"CVE-2010-2337","urls":{"html":"https://cve.report/CVE-2010-2337","api":"https://cve.report/api/cve/CVE-2010-2337.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-2337","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-2337"},"summary":{"title":"CVE-2010-2337","description":"Open redirect vulnerability in RSA Federated Identity Manager 4.0 before 4.0.25 and 4.1 before 4.1.26 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors.","state":"PUBLISHED","assigner":"dell","published_at":"2010-07-28 12:48:52","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/60564","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/60564","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/66504","name":"http://osvdb.org/66504","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2010-07/0187.html","name":"http://archives.neohapsis.com/archives/bugtraq/2010-07/0187.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1024239","name":"http://www.securitytracker.com/id?1024239","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - RSA Federated Identity Manager URL Redirection Flaw Lets Remote Users Bypass Security Controls","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/1880","name":"http://www.vupen.com/english/advisories/2010/1880","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/40704","name":"http://secunia.com/advisories/40704","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA40704 - RSA Federated Identity Manager Redirection Weakness - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/41850","name":"http://www.securityfocus.com/bid/41850","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RSA Federated Identity Manager URI Redirection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://knowledge.rsasecurity.com/scolcms/set.aspx?id=8692","name":"https://knowledge.rsasecurity.com/scolcms/set.aspx?id=8692","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RSA SecurID PASSCODE Request","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-2337","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-2337","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"2337","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rsa","cpe5":"federated_identity_manager","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2337","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rsa","cpe5":"federated_identity_manager","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T02:32:16.414Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1024239","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1024239"},{"name":"20100721 ESA-2010-011: RSA, The Security Division of EMC, announces a fix for potential security vulnerability in RSAR Federated Identity Manager","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2010-07/0187.html"},{"name":"40704","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/40704"},{"name":"41850","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/41850"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://knowledge.rsasecurity.com/scolcms/set.aspx?id=8692"},{"name":"66504","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/66504"},{"name":"ADV-2010-1880","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1880"},{"name":"rsa-redirection-weak-security(60564)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/60564"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-07-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"Open redirect vulnerability in RSA Federated Identity Manager 4.0 before 4.0.25 and 4.1 before 4.1.26 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell"},"references":[{"name":"1024239","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1024239"},{"name":"20100721 ESA-2010-011: RSA, The Security Division of EMC, announces a fix for potential security vulnerability in RSAR Federated Identity Manager","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2010-07/0187.html"},{"name":"40704","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/40704"},{"name":"41850","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/41850"},{"tags":["x_refsource_CONFIRM"],"url":"https://knowledge.rsasecurity.com/scolcms/set.aspx?id=8692"},{"name":"66504","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/66504"},{"name":"ADV-2010-1880","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1880"},{"name":"rsa-redirection-weak-security(60564)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/60564"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","ID":"CVE-2010-2337","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Open redirect vulnerability in RSA Federated Identity Manager 4.0 before 4.0.25 and 4.1 before 4.1.26 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1024239","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1024239"},{"name":"20100721 ESA-2010-011: RSA, The Security Division of EMC, announces a fix for potential security vulnerability in RSAR Federated Identity Manager","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2010-07/0187.html"},{"name":"40704","refsource":"SECUNIA","url":"http://secunia.com/advisories/40704"},{"name":"41850","refsource":"BID","url":"http://www.securityfocus.com/bid/41850"},{"name":"https://knowledge.rsasecurity.com/scolcms/set.aspx?id=8692","refsource":"CONFIRM","url":"https://knowledge.rsasecurity.com/scolcms/set.aspx?id=8692"},{"name":"66504","refsource":"OSVDB","url":"http://osvdb.org/66504"},{"name":"ADV-2010-1880","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/1880"},{"name":"rsa-redirection-weak-security(60564)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/60564"}]}}}},"cveMetadata":{"assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","assignerShortName":"dell","cveId":"CVE-2010-2337","datePublished":"2010-07-27T22:00:00.000Z","dateReserved":"2010-06-18T00:00:00.000Z","dateUpdated":"2024-08-07T02:32:16.414Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-07-28 12:48:52","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rsa:federated_identity_manager:4.0:*:*:*:*:*:*:*","matchCriteriaId":"ADC82DF4-53B5-4308-A68F-C2877960DEA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:rsa:federated_identity_manager:4.1:*:*:*:*:*:*:*","matchCriteriaId":"DEF60540-D484-43AB-B0CA-728B1FCB7E13"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"2337","Ordinal":"1","Title":"CVE-2010-2337","CVE":"CVE-2010-2337","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"2337","Ordinal":"1","NoteData":"Open redirect vulnerability in RSA Federated Identity Manager 4.0 before 4.0.25 and 4.1 before 4.1.26 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors.","Type":"Description","Title":"CVE-2010-2337"},{"CveYear":"2010","CveId":"2337","Ordinal":"2","NoteData":"2010-07-27","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"2337","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}