CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:S/C:P/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
76.5%
Open redirect vulnerability in RSA Federated Identity Manager 4.0 before 4.0.25 and 4.1 before 4.1.26 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors.
Vendor | Product | Version | CPE |
---|---|---|---|
rsa | federated_identity_manager | 4.0 | cpe:2.3:a:rsa:federated_identity_manager:4.0:*:*:*:*:*:*:* |
rsa | federated_identity_manager | 4.1 | cpe:2.3:a:rsa:federated_identity_manager:4.1:*:*:*:*:*:*:* |
archives.neohapsis.com/archives/bugtraq/2010-07/0187.html
osvdb.org/66504
secunia.com/advisories/40704
www.securityfocus.com/bid/41850
www.securitytracker.com/id?1024239
www.vupen.com/english/advisories/2010/1880
exchange.xforce.ibmcloud.com/vulnerabilities/60564
knowledge.rsasecurity.com/scolcms/set.aspx?id=8692