CyberRota Analysis
AI-GeneratedIBM WebSphere Application Server versions 9.0 and 8.5, along with IBM WebSphere Application Server - Liberty, are vulnerable to an open redirect flaw that enables remote attackers to conduct phishing attacks. By tricking users into visiting a malicious site that appears legitimate, attackers can spoof URLs and potentially harvest sensitive information or launch additional attacks. Organizations using these versions should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.