CVE-2015-7428

HIGH

IBM WebSphere Portal <8.0.0.1 CF20, <8.5.0.0 CF09 - Open Redirect

Title source: llm
STIX 2.1

Description

Open redirect vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

References (2)

Core 2
Core References
Various Sources x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21975358
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI51589

Scores

CVSS v3 7.4
EPSS 0.0100
EPSS Percentile 59.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

Details

Status published
Products (3)
ibm/websphere_portal 8.0.0.0
ibm/websphere_portal 8.0.0.1
ibm/websphere_portal 8.5.0.0
Published Feb 29, 2016
Tracked Since Feb 18, 2026