IBM StoredIQ CVE-2019-4166 Open Redirection Vulnerability
BID:108121
CVE-2019-4166 |Info
IBM StoredIQ CVE-2019-4166 Open Redirection Vulnerability
| Bugtraq ID: | 108121 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-4166 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 26 2019 12:00AM |
| Updated: | Apr 26 2019 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
IBM StoredIQ 7.6.0.8 IBM StoredIQ 7.6.0.7 IBM StoredIQ 7.6.0.6 IBM StoredIQ 7.6.0.5 IBM StoredIQ 7.6.0.4 IBM StoredIQ 7.6.0.3 IBM StoredIQ 7.6.0.2 IBM StoredIQ 7.6.0.18 IBM StoredIQ 7.6.0.17 IBM StoredIQ 7.6.0.16 IBM StoredIQ 7.6.0.15 IBM StoredIQ 7.6.0.14 IBM StoredIQ 7.6.0.13 IBM StoredIQ 7.6.0.12 IBM StoredIQ 7.6.0.11 IBM StoredIQ 7.6.0.10 IBM StoredIQ 7.6.0.1 IBM StoredIQ 7.6.0.0 |
| Not Vulnerable: | |
Discussion
IBM StoredIQ CVE-2019-4166 Open Redirection Vulnerability
IBM StoredIQ is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
IBM StoredIQ 7.6.0.0. through 7.6.0.18 are vulnerable.
IBM StoredIQ is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
IBM StoredIQ 7.6.0.0. through 7.6.0.18 are vulnerable.
Exploit / POC
IBM StoredIQ CVE-2019-4166 Open Redirection Vulnerability
To exploit this issue an attacker must entice an unsuspecting user to follow a malicious URI.
To exploit this issue an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
IBM StoredIQ CVE-2019-4166 Open Redirection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM StoredIQ CVE-2019-4166 Open Redirection Vulnerability
References:
References: