| Title | IBM WebSphere Portal などの製品におけるオープンリダイレクトの脆弱性 |
|---|---|
| Summary | WebSphere Portal の IBM WebSphere Portal、IBM Lotus Web Content Management (WCM)、IBM Lotus Workplace Web Content Management、IBM Lotus Quickr サービスの login.jsp には、オープンリダイレクトの脆弱性が存在します。 |
| Possible impacts | 第三者により、クエリ文字列を介して、任意の Web サイトへユーザをリダイレクトされる、およびフィッシング攻撃を実行される可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | Feb. 26, 2010, midnight |
| Registration Date | Sept. 25, 2012, 5:38 p.m. |
| Last Update | Sept. 25, 2012, 5:38 p.m. |
| CVSS2.0 : 警告 | |
| Score | 6.8 |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| IBM |
| IBM Lotus Quickr 8.0, 8.0.0.2、8.1, 8.1.1、および 8.1.1.1 |
| IBM WebSphere Portal |
| Lotus Web Content Management |
| lotus workplace web content management 5.1.0.0 から 5.1.0.5、6.0.0.0 から 6.0.0.4、6.0.1.0 から 6.0.1.7、6.1.0.0 から 6.1.0.3、および 6.1.5.0 |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2012年09月25日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the query string. |
|---|---|
| Publication Date | Feb. 27, 2010, 4:30 a.m. |
| Registration Date | Jan. 29, 2021, 10:57 a.m. |
| Last Update | Oct. 11, 2018, 4:53 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:ibm:websphere_portal:5.1.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:5.1.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:5.1.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:5.1.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:5.1.0.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:5.1.0.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.0.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.1.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.1.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.1.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.1.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.1.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.1.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.1.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.0.1.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.1.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.1.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.1.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.1.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:websphere_portal:6.1.5.0:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:ibm:lotus_web_content_management:5.1.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:5.1.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:5.1.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:5.1.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:5.1.0.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:5.1.0.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.0.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.1.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.1.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.1.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.1.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.1.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.1.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.1.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.0.1.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.1.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.1.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.1.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.1.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_web_content_management:6.1.5.0:*:*:*:*:*:*:* | |||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:5.1.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:5.1.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:5.1.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:5.1.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:5.1.0.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:5.1.0.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.0.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.1.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.1.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.1.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.1.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.1.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.1.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.1.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.0.1.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.1.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.1.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.1.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.1.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_workplace_web_content_management:6.1.5.0:*:*:*:*:*:*:* | |||||
| Configuration4 | or higher | or less | more than | less than | |
| cpe:2.3:a:ibm:lotus_quickr:8.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_quickr:8.0.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_quickr:8.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_quickr:8.1.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:ibm:lotus_quickr:8.1.1.1:*:*:*:*:*:*:* | |||||