Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2018-10-05 CVE-2018-15403 Open Redirect vulnerability in Cisco products
A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker to redirect a user to a malicious web page.
network
low complexity
cisco CWE-601
5.4
2018-10-04 CVE-2018-11784 Open Redirect vulnerability in multiple products
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g.
network
low complexity
apache debian canonical netapp redhat oracle CWE-601
4.3
2018-10-01 CVE-2018-17870 Open Redirect vulnerability in Btiteam Xbtit 2.54
An issue was discovered in BTITeam XBTIT 2.5.4.
network
low complexity
btiteam CWE-601
6.1
2018-09-28 CVE-2018-1251 Open Redirect vulnerability in Dell EMC Unity Firmware and EMC Unityvsa
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability.
network
low complexity
dell CWE-601
8.1
2018-09-28 CVE-2018-1704 Open Redirect vulnerability in IBM Platform Symphony and Spectrum Symphony
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
5.4
2018-09-27 CVE-2018-1736 Open Redirect vulnerability in IBM Websphere Portal
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.1
2018-09-18 CVE-2018-16954 Open Redirect vulnerability in Oracle Webcenter Interaction 10.3.3
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3.
network
low complexity
oracle CWE-601
6.1
2018-09-16 CVE-2018-17074 Open Redirect vulnerability in Feed Statistics Project Feed Statistics
The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.
network
low complexity
feed-statistics-project CWE-601
6.1
2018-09-13 CVE-2018-5548 Open Redirect vulnerability in F5 Big-Ip Access Policy Manager 11.6.1/11.6.2/11.6.3
On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher texts.
network
low complexity
f5 CWE-601
6.1
2018-09-09 CVE-2018-16761 Open Redirect vulnerability in Eventum Project Eventum
Eventum before 3.4.0 has an open redirect vulnerability.
network
low complexity
eventum-project CWE-601
6.1