IBM Security Bulletin: Unvalidated redirection URL vulnerability in IBM Marketing Platform (CVE-2016-0228)
IBM Marketing Platform allows a remote attacker to specify a malicious url while creating portlets which then can be redirected to that url while opening that portlet in a dashboard. An attacker could exploit this vulnerability to redirect a victim to arbitrary Web sites. IBM Marketing Platform has addressed this vulnerability.
CVE(s): CVE-2016-0228
Affected product(s) and affected version(s):
IBM Marketing Platform 10.0
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2nMGWtG
X-Force Database: http://ift.tt/2phoMNM
The post IBM Security Bulletin: Unvalidated redirection URL vulnerability in IBM Marketing Platform (CVE-2016-0228) appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team http://ift.tt/2nMG5t3