vendor:
IBM Security Verify Access
by:
Anonymous
7.1
CVSS
HIGH
Open Redirect
601
CWE
Product Name: IBM Security Verify Access
Affected Version From: 10.0.0
Affected Version To: 10.0.8
Patch Exists: YES
Related CWE: CVE-2024-35133
CPE: a:ibm:security_verify_access:10.0.0
Platforms Tested:
2024
IBM Security Verify Access 10.0.0 – Open Redirect Vulnerability in OAuth Flow
By tricking a user into visiting a malicious website, an attacker could exploit this vulnerability in IBM Security Verify Access 10.0.0 - 10.0.8 to redirect the user to a different site that appears legitimate, potentially leading to the disclosure of sensitive information or enabling further attacks.
Mitigation:
To mitigate this vulnerability, users should avoid clicking on untrusted links and verify URLs before entering sensitive information. IBM Security Verify Access users are advised to update to the latest version to prevent exploitation of this issue.