Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 83383.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://www-01.ibm.com/support/docview.wss?uid=swg21671622 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/83383 | vdb entry vendor advisory |