IBM Security Bulletin: Unvalidated redirection URL vulnerability in IBM Marketing Platform (CVE-2016-0228)

IBM Marketing Platform allows a remote attacker to specify a malicious url while creating portlets which then can be redirected to that url while opening that portlet in a dashboard. An attacker could exploit this vulnerability to redirect a victim to arbitrary Web sites. IBM Marketing Platform has addressed this vulnerability.

CVE(s): CVE-2016-0228

Affected product(s) and affected version(s):

IBM Marketing Platform 10.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2nMGWtG
X-Force Database: http://ift.tt/2phoMNM

The post IBM Security Bulletin: Unvalidated redirection URL vulnerability in IBM Marketing Platform (CVE-2016-0228) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2nMG5t3