CVE-2020-4653
Last modified
CVE-2020-4653 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. EPSS estimates a 0.71% chance of exploitation in the next 30 days.
Description
IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Planning Analytics | 2.0 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/186082VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6254788Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/186082VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6254788Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-4653?
How severe is CVE-2020-4653?
How do I fix CVE-2020-4653?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-4646IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through…4.3
- CVE-2020-4647IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.…8.8
- CVE-2020-4648A vulnerability exsists in IBM Planning Analytics 2.0 whereb…6.5
- CVE-2020-4649IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analyt…4.3
- CVE-2020-4650IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.…3.3
- CVE-2020-4651IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.…4.8
- CVE-2020-4654IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allo…6.5
- CVE-2020-4655IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through…8.8
- CVE-2020-4657IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard…6.1
- CVE-2020-4658IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnera…6.1
- CVE-2020-4660IBM Security Access Manager 9.0.7 and IBM Security Verify Ac…5.3
- CVE-2020-4661IBM Security Access Manager 9.0.7 and IBM Security Verify Ac…5.3
Are you affected by CVE-2020-4653?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
