DNA View

CVE-2019-4092

Medium
Low Medium High Critical
6.1
CVSS Score
Published: Apr 25, 2019
Last Modified: Nov 21, 2024

Vulnerability Description

IBM Content Navigator 2.0.3 and 3.0CD could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 157654.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
R
Scope
C
Confidentiality
L
Integrity
L
Availability
N

Known Affected Software

2 configuration(s) from 1 vendor(s)

content_navigator
Version:
2.0.0
CPE:
cpe:2.3:a:ibm:content_navigator:2.0.0:*:*:*:*:*:*:*
content_navigator
Version:
3.0.0
CPE:
cpe:2.3:a:ibm:content_navigator:3.0.0:*:*:*:continuous_delivery:*:*:*
This vulnerability affects 2 software configuration(s). Ensure you patch all affected systems.

Severity Details

6.1
out of 10.0
Medium

Weakness Type (CWE)

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Exploit Likelihood
Low
Typical Severity
High
Abstraction Level
Base

Key Information

Published Date
April 25, 2019