Lucene search

K
cveMitreCVE-2008-4284
HistoryFeb 10, 2009 - 10:30 p.m.

CVE-2008-4284

2009-02-1022:30:00
CWE-59
mitre
web.nvd.nist.gov
35
ibm
websphere
application server
open redirect
vulnerability
cve-2008-4284
nvd

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

AI Score

6.8

Confidence

High

EPSS

0.003

Percentile

68.5%

Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x before 6.0.2.33, and 6.1.x before 6.1.0.23 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage feature.

Affected configurations

Nvd
Node
ibmwebsphere_application_serverMatch5.0
OR
ibmwebsphere_application_serverMatch5.0z_os
OR
ibmwebsphere_application_serverMatch5.0.0
OR
ibmwebsphere_application_serverMatch5.0.1
OR
ibmwebsphere_application_serverMatch5.0.2
OR
ibmwebsphere_application_serverMatch5.0.2.1
OR
ibmwebsphere_application_serverMatch5.0.2.2
OR
ibmwebsphere_application_serverMatch5.0.2.3
OR
ibmwebsphere_application_serverMatch5.0.2.4
OR
ibmwebsphere_application_serverMatch5.0.2.5
OR
ibmwebsphere_application_serverMatch5.0.2.6
OR
ibmwebsphere_application_serverMatch5.0.2.7
OR
ibmwebsphere_application_serverMatch5.0.2.8
OR
ibmwebsphere_application_serverMatch5.0.2.9
OR
ibmwebsphere_application_serverMatch5.0.2.10
OR
ibmwebsphere_application_serverMatch5.0.2.11
OR
ibmwebsphere_application_serverMatch5.0.2.12
OR
ibmwebsphere_application_serverMatch5.0.2.13
OR
ibmwebsphere_application_serverMatch5.0.2.14
OR
ibmwebsphere_application_serverMatch5.0.2.15
OR
ibmwebsphere_application_serverMatch5.0.2.16
OR
ibmwebsphere_application_serverMatch5.1.0
OR
ibmwebsphere_application_serverMatch5.1.0.2
OR
ibmwebsphere_application_serverMatch5.1.0.3
OR
ibmwebsphere_application_serverMatch5.1.0.4
OR
ibmwebsphere_application_serverMatch5.1.0.5
OR
ibmwebsphere_application_serverMatch5.1.1
OR
ibmwebsphere_application_serverMatch5.1.1.1
OR
ibmwebsphere_application_serverMatch5.1.1.10
OR
ibmwebsphere_application_serverMatch5.1.1.11
OR
ibmwebsphere_application_serverMatch5.1.1.12
OR
ibmwebsphere_application_serverMatch5.1.1.13
OR
ibmwebsphere_application_serverMatch5.1.1.14
OR
ibmwebsphere_application_serverMatch5.1.1.15
OR
ibmwebsphere_application_serverMatch5.1.1.16
OR
ibmwebsphere_application_serverMatch5.1.1.17
OR
ibmwebsphere_application_serverMatch5.1.1.18
OR
ibmwebsphere_application_serverMatch5.1.1.19
OR
ibmwebsphere_application_serverMatch6.0
OR
ibmwebsphere_application_serverMatch6.0.0.1
OR
ibmwebsphere_application_serverMatch6.0.0.2
OR
ibmwebsphere_application_serverMatch6.0.0.3
OR
ibmwebsphere_application_serverMatch6.0.1
OR
ibmwebsphere_application_serverMatch6.0.1.1
OR
ibmwebsphere_application_serverMatch6.0.1.2
OR
ibmwebsphere_application_serverMatch6.0.1.3
OR
ibmwebsphere_application_serverMatch6.0.1.5
OR
ibmwebsphere_application_serverMatch6.0.1.7
OR
ibmwebsphere_application_serverMatch6.0.1.9
OR
ibmwebsphere_application_serverMatch6.0.1.11
OR
ibmwebsphere_application_serverMatch6.0.1.13
OR
ibmwebsphere_application_serverMatch6.0.1.15
OR
ibmwebsphere_application_serverMatch6.0.1.17
OR
ibmwebsphere_application_serverMatch6.0.2
OR
ibmwebsphere_application_serverMatch6.0.2.1
OR
ibmwebsphere_application_serverMatch6.0.2.2
OR
ibmwebsphere_application_serverMatch6.0.2.3
OR
ibmwebsphere_application_serverMatch6.0.2.4
OR
ibmwebsphere_application_serverMatch6.0.2.5
OR
ibmwebsphere_application_serverMatch6.0.2.6
OR
ibmwebsphere_application_serverMatch6.0.2.7
OR
ibmwebsphere_application_serverMatch6.0.2.9
OR
ibmwebsphere_application_serverMatch6.0.2.11
OR
ibmwebsphere_application_serverMatch6.0.2.13
OR
ibmwebsphere_application_serverMatch6.0.2.15
OR
ibmwebsphere_application_serverMatch6.0.2.17
OR
ibmwebsphere_application_serverMatch6.0.2.19
OR
ibmwebsphere_application_serverMatch6.0.2.22
OR
ibmwebsphere_application_serverMatch6.0.2.23
OR
ibmwebsphere_application_serverMatch6.0.2.24
OR
ibmwebsphere_application_serverMatch6.0.2.25
OR
ibmwebsphere_application_serverMatch6.0.2.27
OR
ibmwebsphere_application_serverMatch6.0.2.28
OR
ibmwebsphere_application_serverMatch6.0.2.29
OR
ibmwebsphere_application_serverMatch6.0.2.30
OR
ibmwebsphere_application_serverMatch6.0.2.31
OR
ibmwebsphere_application_serverMatch6.0.2.32
OR
ibmwebsphere_application_serverMatch6.1
OR
ibmwebsphere_application_serverMatch6.1.0
OR
ibmwebsphere_application_serverMatch6.1.0.0
OR
ibmwebsphere_application_serverMatch6.1.0.1
OR
ibmwebsphere_application_serverMatch6.1.0.2
OR
ibmwebsphere_application_serverMatch6.1.0.3
OR
ibmwebsphere_application_serverMatch6.1.0.4
OR
ibmwebsphere_application_serverMatch6.1.0.5
OR
ibmwebsphere_application_serverMatch6.1.0.6
OR
ibmwebsphere_application_serverMatch6.1.0.7
OR
ibmwebsphere_application_serverMatch6.1.0.8
OR
ibmwebsphere_application_serverMatch6.1.0.9
OR
ibmwebsphere_application_serverMatch6.1.0.10
OR
ibmwebsphere_application_serverMatch6.1.0.11
OR
ibmwebsphere_application_serverMatch6.1.0.12
OR
ibmwebsphere_application_serverMatch6.1.0.13
OR
ibmwebsphere_application_serverMatch6.1.0.14
OR
ibmwebsphere_application_serverMatch6.1.0.15
OR
ibmwebsphere_application_serverMatch6.1.0.16
OR
ibmwebsphere_application_serverMatch6.1.0.17
OR
ibmwebsphere_application_serverMatch6.1.0.18
OR
ibmwebsphere_application_serverMatch6.1.0.19
OR
ibmwebsphere_application_serverMatch6.1.0.20
OR
ibmwebsphere_application_serverMatch6.1.0.21
OR
ibmwebsphere_application_serverMatch6.1.0.22
OR
ibmwebsphere_application_serverMatch6.1.1
OR
ibmwebsphere_application_serverMatch6.1.3
OR
ibmwebsphere_application_serverMatch6.1.5
OR
ibmwebsphere_application_serverMatch6.1.6
OR
ibmwebsphere_application_serverMatch6.1.7
OR
ibmwebsphere_application_serverMatch6.1.13
OR
ibmwebsphere_application_serverMatch6.1.14
VendorProductVersionCPE
ibmwebsphere_application_server5.0cpe:2.3:a:ibm:websphere_application_server:5.0:*:*:*:*:*:*:*
ibmwebsphere_application_server5.0cpe:2.3:a:ibm:websphere_application_server:5.0:*:z_os:*:*:*:*:*
ibmwebsphere_application_server5.0.0cpe:2.3:a:ibm:websphere_application_server:5.0.0:*:*:*:*:*:*:*
ibmwebsphere_application_server5.0.1cpe:2.3:a:ibm:websphere_application_server:5.0.1:*:*:*:*:*:*:*
ibmwebsphere_application_server5.0.2cpe:2.3:a:ibm:websphere_application_server:5.0.2:*:*:*:*:*:*:*
ibmwebsphere_application_server5.0.2.1cpe:2.3:a:ibm:websphere_application_server:5.0.2.1:*:*:*:*:*:*:*
ibmwebsphere_application_server5.0.2.2cpe:2.3:a:ibm:websphere_application_server:5.0.2.2:*:*:*:*:*:*:*
ibmwebsphere_application_server5.0.2.3cpe:2.3:a:ibm:websphere_application_server:5.0.2.3:*:*:*:*:*:*:*
ibmwebsphere_application_server5.0.2.4cpe:2.3:a:ibm:websphere_application_server:5.0.2.4:*:*:*:*:*:*:*
ibmwebsphere_application_server5.0.2.5cpe:2.3:a:ibm:websphere_application_server:5.0.2.5:*:*:*:*:*:*:*
Rows per page:
1-10 of 1091

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

AI Score

6.8

Confidence

High

EPSS

0.003

Percentile

68.5%

Related for CVE-2008-4284