216.73.216.233

CVE-2024-35133

· Published 29/08/2024 17:15 · Modified 21/09/2024 10:15

Labels: CVE-2024-35133 2024-08-29CVE-2024-35133CWE-601[email protected]

Essential information

Published
29/08/2024 17:15
Modified
21/09/2024 10:15
Author
Creator
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

CVSS metrics

Description

IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

NVD status

Status
Modified — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ibm / security verify access cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
ibm / security verify access docker cpe:2.3:a:ibm:security_verify_access_docker:*:*:*:*:*:*:*:*

References