PT-2025-26503 · Ibm · Ibm Process Mining

CVE-2025-36016

·

Published

2025-06-21

·

Updated

2025-06-21

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions: IBM Process Mining versions 2.0.1 through 2.0.1 IF001
Description: The issue allows a remote attacker to conduct phishing attacks using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this to spoof the URL displayed, redirecting a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Recommendations: For IBM Process Mining versions 2.0.1 through 2.0.1 IF001, consider restricting access to the affected Web site to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using links from untrusted sources to prevent redirecting to malicious Web sites.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09711
CVE-2025-36016

Affected Products

Ibm Process Mining