CVE-2018-1736

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 147906.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.4 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
ibmCNA
7.4 HIGH
NETWORK
LOW
NONE
CVSS:3.0/A:N/AC:L/AV:N/C:N/I:H/PR:N/S:C/UI:R/E:U/RC:C/RL:O
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
VendorProductVersion
ibmwebsphere_portal
7.0.0.0
ibmwebsphere_portal
7.0.0.1
ibmwebsphere_portal
7.0.0.1:cf002
ibmwebsphere_portal
7.0.0.1:cf003
ibmwebsphere_portal
7.0.0.1:cf004
ibmwebsphere_portal
7.0.0.1:cf005
ibmwebsphere_portal
7.0.0.1:cf006
ibmwebsphere_portal
7.0.0.1:cf007
ibmwebsphere_portal
7.0.0.1:cf008
ibmwebsphere_portal
7.0.0.1:cf009
ibmwebsphere_portal
7.0.0.1:cf010
ibmwebsphere_portal
7.0.0.1:cf011
ibmwebsphere_portal
7.0.0.1:cf012
ibmwebsphere_portal
7.0.0.1:cf013
ibmwebsphere_portal
7.0.0.1:cf014
ibmwebsphere_portal
7.0.0.1:cf015
ibmwebsphere_portal
7.0.0.1:cf016
ibmwebsphere_portal
7.0.0.1:cf017
ibmwebsphere_portal
7.0.0.1:cf018
ibmwebsphere_portal
7.0.0.1:cf019
ibmwebsphere_portal
7.0.0.1:cf020
ibmwebsphere_portal
7.0.0.2
ibmwebsphere_portal
7.0.0.2:cf011
ibmwebsphere_portal
7.0.0.2:cf012
ibmwebsphere_portal
7.0.0.2:cf013
ibmwebsphere_portal
7.0.0.2:cf014
ibmwebsphere_portal
7.0.0.2:cf015
ibmwebsphere_portal
7.0.0.2:cf016
ibmwebsphere_portal
7.0.0.2:cf017
ibmwebsphere_portal
7.0.0.2:cf018
ibmwebsphere_portal
7.0.0.2:cf019
ibmwebsphere_portal
7.0.0.2:cf020
ibmwebsphere_portal
7.0.0.2:cf021
ibmwebsphere_portal
7.0.0.2:cf022
ibmwebsphere_portal
7.0.0.2:cf023
ibmwebsphere_portal
7.0.0.2:cf024
ibmwebsphere_portal
7.0.0.2:cf025
ibmwebsphere_portal
7.0.0.2:cf026
ibmwebsphere_portal
7.0.0.2:cf027
ibmwebsphere_portal
7.0.0.2:cf028
ibmwebsphere_portal
7.0.0.2:cf029
ibmwebsphere_portal
7.0.0.2:cf030
ibmwebsphere_portal
8.0.0.0
ibmwebsphere_portal
8.0.0.0:cf01
ibmwebsphere_portal
8.0.0.0:cf02
ibmwebsphere_portal
8.0.0.0:cf03
ibmwebsphere_portal
8.0.0.0:cf04
ibmwebsphere_portal
8.0.0.0:cf05
ibmwebsphere_portal
8.0.0.0:cf06
ibmwebsphere_portal
8.0.0.1
ibmwebsphere_portal
8.0.0.1:cf04
ibmwebsphere_portal
8.0.0.1:cf05
ibmwebsphere_portal
8.0.0.1:cf06
ibmwebsphere_portal
8.0.0.1:cf07
ibmwebsphere_portal
8.0.0.1:cf08
ibmwebsphere_portal
8.0.0.1:cf09
ibmwebsphere_portal
8.0.0.1:cf10
ibmwebsphere_portal
8.0.0.1:cf11
ibmwebsphere_portal
8.0.0.1:cf12
ibmwebsphere_portal
8.0.0.1:cf13
ibmwebsphere_portal
8.0.0.1:cf14
ibmwebsphere_portal
8.0.0.1:cf15
ibmwebsphere_portal
8.0.0.1:cf16
ibmwebsphere_portal
8.0.0.1:cf17
ibmwebsphere_portal
8.0.0.1:cf18
ibmwebsphere_portal
8.0.0.1:cf19
ibmwebsphere_portal
8.0.0.1:cf20
ibmwebsphere_portal
8.0.0.1:cf21
ibmwebsphere_portal
8.0.0.1:cf22
ibmwebsphere_portal
8.0.0.1:cf23
ibmwebsphere_portal
8.5.0.0
ibmwebsphere_portal
8.5.0.0:cf01
ibmwebsphere_portal
8.5.0.0:cf02
ibmwebsphere_portal
8.5.0.0:cf03
ibmwebsphere_portal
8.5.0.0:cf04
ibmwebsphere_portal
8.5.0.0:cf05
ibmwebsphere_portal
8.5.0.0:cf06
ibmwebsphere_portal
8.5.0.0:cf07
ibmwebsphere_portal
8.5.0.0:cf08
ibmwebsphere_portal
8.5.0.0:cf09
ibmwebsphere_portal
8.5.0.0:cf10
ibmwebsphere_portal
8.5.0.0:cf11
ibmwebsphere_portal
8.5.0.0:cf12
ibmwebsphere_portal
8.5.0.0:cf13
ibmwebsphere_portal
8.5.0.0:cf14
ibmwebsphere_portal
8.5.0.0:cf15
ibmwebsphere_portal
9.0.0.0
ibmwebsphere_portal
9.0.0.0:cf14
ibmwebsphere_portal
9.0.0.0:cf15
𝑥
= Vulnerable software versions