IBM Sterling Control Center CVE-2014-0925 Open Redirection Vulnerability
BID:67694
Info
IBM Sterling Control Center CVE-2014-0925 Open Redirection Vulnerability
| Bugtraq ID: | 67694 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0925 |
| Remote: | Yes |
| Local: | No |
| Published: | May 16 2014 12:00AM |
| Updated: | May 16 2014 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Sterling Control Center 5.4 1 IBM Sterling Control Center 5.4.1 IBM Sterling Control Center 5.4 IBM Sterling Control Center 5.3 IBM Sterling Control Center 5.2 |
| Not Vulnerable: | |
Discussion
IBM Sterling Control Center CVE-2014-0925 Open Redirection Vulnerability
IBM Sterling Control Center is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
IBM Sterling Control Center 5.2, 5.3, 5.4, 5.4.0.1 and 5.4.1 are vulnerable.
IBM Sterling Control Center is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
IBM Sterling Control Center 5.2, 5.3, 5.4, 5.4.0.1 and 5.4.1 are vulnerable.
Exploit / POC
IBM Sterling Control Center CVE-2014-0925 Open Redirection Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
IBM Sterling Control Center CVE-2014-0925 Open Redirection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Sterling Control Center CVE-2014-0925 Open Redirection Vulnerability
References:
References: