Multiple IBM Products CVE-2017-1534 Unspecified Open Redirect Vulnerability
BID:102509
CVE-2017-1534 |Info
Multiple IBM Products CVE-2017-1534 Unspecified Open Redirect Vulnerability
| Bugtraq ID: | 102509 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2017-1534 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2018 12:00AM |
| Updated: | Jan 05 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
IBM Security Access Manager for Web 8.0.1.6 IBM Security Access Manager for Web 8.0.1.5 IBM Security Access Manager for Web 8.0.1.4 IBM Security Access Manager for Web 8.0.1.3 IBM Security Access Manager for Web 8.0.1.2 IBM Security Access Manager for Web 8.0.1.1 IBM Security Access Manager for Web 8.0.1.0 IBM Security Access Manager for Web 8.0 IBM Security Access Manager for Mobile 8.0.1.6 IBM Security Access Manager for Mobile 8.0.1.5 IBM Security Access Manager for Mobile 8.0.1.4 IBM Security Access Manager for Mobile 8.0.1.3 IBM Security Access Manager for Mobile 8.0.1.2 IBM Security Access Manager for Mobile 8.0.1.1 IBM Security Access Manager for Mobile 8.0.0.3 IBM Security Access Manager for Mobile 8.0.0.2 IBM Security Access Manager for Mobile 8.0.0.1 IBM Security Access Manager for Mobile 8.0.0.0 IBM Security Access Manager 9.0.3.0 IBM Security Access Manager 9.0.2.0 IBM Security Access Manager 9.0.1.0 IBM Security Access Manager 9.0.0.1 IBM Security Access Manager 9.0 |
| Not Vulnerable: | |
Discussion
Multiple IBM Products CVE-2017-1534 Unspecified Open Redirect Vulnerability
Multiple IBM Products are prone to an unspecified open redirect vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
The following versions are affected:
IBM Security Access Manager for Web 8.0 through 8.0.1.6
IBM Security Access Manager for Mobile 8.0 through 8.0.1.6
IBM Security Access Manager 9.0 through 9.0.3.0
Multiple IBM Products are prone to an unspecified open redirect vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
The following versions are affected:
IBM Security Access Manager for Web 8.0 through 8.0.1.6
IBM Security Access Manager for Mobile 8.0 through 8.0.1.6
IBM Security Access Manager 9.0 through 9.0.3.0
Exploit / POC
Multiple IBM Products CVE-2017-1534 Unspecified Open Redirect Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple IBM Products CVE-2017-1534 Unspecified Open Redirect Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple IBM Products CVE-2017-1534 Unspecified Open Redirect Vulnerability
References:
References: