IBM Jazz Reporting Service CVE-2019-4201 Open Redirection Vulnerability
BID:108754
Info
IBM Jazz Reporting Service CVE-2019-4201 Open Redirection Vulnerability
| Bugtraq ID: | 108754 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-4201 |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2019 12:00AM |
| Updated: | May 24 2019 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
IBM Jazz Reporting Service 1.1.3.2 IBM Jazz Reporting Service 1.1.3 |
| Not Vulnerable: | |
Discussion
IBM Jazz Reporting Service CVE-2019-4201 Open Redirection Vulnerability
IBM Jazz Reporting Service is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Jazz for Service Management version 1.1.3 through 1.1.3.2 are vulnerable.
IBM Jazz Reporting Service is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Jazz for Service Management version 1.1.3 through 1.1.3.2 are vulnerable.
Exploit / POC
IBM Jazz Reporting Service CVE-2019-4201 Open Redirection Vulnerability
To exploit this issue an attacker must entice an unsuspecting user to follow a malicious URI.
To exploit this issue an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
IBM Jazz Reporting Service CVE-2019-4201 Open Redirection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Jazz Reporting Service CVE-2019-4201 Open Redirection Vulnerability
References:
References: