← Back to CVE List
Vulnerability Intelligence Report

CVE-2017-1748

IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 135521.

No Active Exploit Signals
CVSS Base Score
6.8
MEDIUM
Exploitability:2.3
Impact Score:4.0
Temporal Score:5.9
EPSS Probability:0.93%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
IBM Connections 5.0 (affected), 5.5 (affected), 6.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.932%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityIBM Corporation · Vendor · USA
Reserved2016-11-30T00:00:00
Published2018-06-04T17:00:00
Patch Date2018-05-30
Last Updated2024-09-16T19:00:52

LINK COPIED TO CLIPBOARD