PT-2014-3951 · Ibm · Ibm Sterling Control Center

Published

2014-05-30

·

Updated

2017-08-29

·

CVE-2014-0925

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling Control Center versions 5.4.0 through 5.4.0.1 before iFix 3 IBM Sterling Control Center versions 5.4.1 through 5.4.1.0 before iFix 2
Description The issue allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
Recommendations For IBM Sterling Control Center versions 5.4.0 through 5.4.0.1 before iFix 3, apply iFix 3 to resolve the issue. For IBM Sterling Control Center versions 5.4.1 through 5.4.1.0 before iFix 2, apply iFix 2 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2014-0925

Affected Products

Ibm Sterling Control Center