could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
No analysis available yet.
Vendor Solution
IBM strongly recommends addressing the vulnerability now by upgrading. Affected Product(s)VersionFixIBM Cognos Command Center10.2.5 IBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central https://www.ibm.com/support/pages/node/7239167 IBM Cognos Command Center10.2.4.1 IBM Cognos Command Center 10.2.5 FP1 IF1 available for download from Fix Central https://www.ibm.com/support/pages/node/7239167
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25812 | IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7242159 |
|
Tue, 26 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 Aug 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. | |
| Title | IBM Cognos Command Center HTTP Open Redirect | |
| First Time appeared |
Ibm
Ibm cognos Command Center |
|
| Weaknesses | CWE-601 | |
| CPEs | cpe:2.3:a:ibm:cognos_command_center:10.2.4.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:cognos_command_center:10.2.5:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm cognos Command Center |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-26T17:36:08.348Z
Reserved: 2025-03-23T16:28:25.483Z
Link: CVE-2025-2697
Updated: 2025-08-26T17:36:05.780Z
Status : Analyzed
Published: 2025-08-26T17:15:37.320
Modified: 2025-09-02T18:06:52.323
Link: CVE-2025-2697
No data.
OpenCVE Enrichment
No data.
EUVD