Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-35133

Опубликовано: 29 авг. 2024
Источник: nvd
CVSS3: 6.8
CVSS3: 8.2
EPSS Низкий

Описание

IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
Версия от 10.0.0 (включая) до 10.0.8 (включая)
cpe:2.3:a:ibm:security_verify_access_docker:*:*:*:*:*:*:*:*
Версия от 10.0.0 (включая) до 10.0.8 (включая)

EPSS

Процентиль: 84%
0.02137
Низкий

6.8 Medium

CVSS3

8.2 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.8
github
больше 1 года назад

IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

EPSS

Процентиль: 84%
0.02137
Низкий

6.8 Medium

CVSS3

8.2 High

CVSS3

Дефекты

CWE-601