Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-36016

Опубликовано: 21 июн. 2025
Источник: nvd
CVSS3: 6.8
CVSS3: 8.2
EPSS Низкий

Описание

IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:process_mining:2.0.1:-:*:*:*:*:*:*
cpe:2.3:a:ibm:process_mining:2.0.1:interim_fix_001:*:*:*:*:*:*

EPSS

Процентиль: 13%
0.00042
Низкий

6.8 Medium

CVSS3

8.2 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.8
github
8 месяцев назад

IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

CVSS3: 6.8
fstec
8 месяцев назад

Уязвимость программного обеспечения для анализа и улучшения бизнес-процессов IBM Process Mining, связанная с переадресацией URL на ненадежный сайт при загрузке страницы входа, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 13%
0.00042
Низкий

6.8 Medium

CVSS3

8.2 High

CVSS3

Дефекты

CWE-601