CVE-2016-3040
MEDIUMIBM Security Privileged Identity Mana... - Open Redirect
Title source: ruleDescription
IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Scores
CVSS v3
6.8
EPSS
0.0011
EPSS Percentile
29.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
Classification
CWE
CWE-601
Status
published
Affected Products (2)
ibm/security_privileged_identity_manager_virtual_appliance
n/a/n/a
Timeline
Published
Sep 26, 2016
Tracked Since
Feb 18, 2026