Lucene search

K
cvelistIbmCVELIST:CVE-2017-1159
HistoryMay 22, 2017 - 8:00 p.m.

CVE-2017-1159

2017-05-2220:00:00
ibm
www.cve.org

5.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.4%

IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 122891.

CNA Affected

[
  {
    "product": "Business Process Manager Advanced",
    "vendor": "IBM Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "8.0, 8.0.1, 8.0.1.1, 8.0.1.2, 8.5, 8.5.0.1, 8.5.5, 8.0.1.3, 8.5.6, 8.5.0.2, 8.5.7, 8.5.7.CF201609, 8.5.6.1, 8.5.6.2, 8.5.7.CF201606, 8.5.7.CF201612"
      }
    ]
  }
]

5.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.4%

Related for CVELIST:CVE-2017-1159