CVE-2024-35133
MEDIUM
IBM Security Verify Access HTTP open redirect
Record summary
CVE-2024-35133 has a selected CVSS score of 6.8 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Description source: CVE List
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Security Verify AccessBrowse IBM / Security Verify AccessDefault status: unaffected | CVE List | 10.0.0 to ≤ 10.0.8 | affected |
Security Verify Access DockerBrowse IBM / Security Verify Access DockerDefault status: unaffected | CVE List | 10.0.0 to ≤ 10.0.8 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBIBM Security Verify Access 10.0.0 - Open Redirect during OAuth FlowExploitDB exploitby Giulio GarziaNot analyzed1 file
Repository PoCs
GitHubOzozuz/IBM-Security-Verify-oAuth_Token_Steal-CVE-2024-35133Repository PoCby OzozuzStars: 2Not analyzed2 files
References
3exchange.xforce.ibmcloud.comvdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/291026 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-35133 ibm.comVendor advisory
https://www.ibm.com/support/pages/node/7166712