CVE Vulnerabilities

CVE-2014-8894

Published: Jan 29, 2015 | Modified: Sep 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Open redirect vulnerability in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the out parameter.

Affected Software

Name Vendor Start Version End Version
Tririga_application_platform Ibm 3.2.1 (including) 3.2.1 (including)
Tririga_application_platform Ibm 3.3.2.0 (including) 3.3.2.0 (including)
Tririga_application_platform Ibm 3.3.2.1 (including) 3.3.2.1 (including)
Tririga_application_platform Ibm 3.3.2.2 (including) 3.3.2.2 (including)
Tririga_application_platform Ibm 3.4.0.0 (including) 3.4.0.0 (including)
Tririga_application_platform Ibm 3.4.0.1 (including) 3.4.0.1 (including)
Tririga_application_platform Ibm 3.4.1.0 (including) 3.4.1.0 (including)

References