Impact
IBM WebSphere Application Server prior to version 9.0.5.29 and 8.5.5.31 contains an open‑redirect flaw, classified as CWE‑601, that allows a remote attacker to craft a URL which, when visited by a user, displays a spoofed address bar while redirecting the browser to a malicious site. This can enable phishing attacks, credential theft, and may serve as a foothold for further compromise of sensitive data.
Affected Systems
Affected products are IBM WebSphere Application Server 9.0 and 8.5, including the Liberty profile. Vulnerable releases include IBM WebSphere Application Server versions from 9.0.0.0 through 9.0.5.28 and from 8.5.0.0 through 8.5.5.30.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5 and is not listed in the CISA KEV catalog. The EPSS score of 0.0022 (less than 1%) indicates a very low exploitation probability. The likely attack vector is remote, requiring only that an end‑user click a malicious link; no privileged access or technical exploitation is required beyond forging the URL. Consequently, the risk is moderate, driven mainly by user interaction and the potential to steal credentials or deliver malware via phishing.
OpenCVE Enrichment