Record summary

CVE-2024-35133 has a selected CVSS score of 6.8 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 29, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List10.0.0 to ≤ 10.0.8affected

Security Verify Access Docker

Browse IBM / Security Verify Access Docker

Default status: unaffected

CVE List10.0.0 to ≤ 10.0.8affected

Proofs of concept

2

Catalogued exploits

ExploitDBIBM Security Verify Access 10.0.0 - Open Redirect during OAuth FlowExploitDB exploitby Giulio GarziaNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubOzozuz/IBM-Security-Verify-oAuth_Token_Steal-CVE-2024-35133Repository PoCby OzozuzStars: 2Not analyzed2 files

6.6 KiB

GitHub

PoC details

References

3