Vulnerabilities > CVE-2014-0925 - Open Redirection vulnerability in IBM Sterling Control Center 5.4.0/5.4.0.1/5.4.1.0
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
SINGLE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE network
ibm
Summary
Open redirect vulnerability in IBM Sterling Control Center 5.4.0 before 5.4.0.1 iFix 3 and 5.4.1 before 5.4.1.0 iFix 2 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. Per: http://cwe.mitre.org/data/definitions/601.html CWE-601: URL Redirection to Untrusted Site
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |