Open redirect in Operational Decision Manager - CVE-2025-2824

 

Open redirect in Operational Decision Manager - CVE-2025-2824

Published: August 5, 2025


Vulnerability identifier: #VU113623
CSH Severity: Medium
CVSS v4: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:H/SA:N]
CVE-ID: CVE-2025-2824
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect victims to arbitrary URL.

The vulnerability exists due to improper sanitization of user-supplied data. A remote attacker can trick the victim into visiting a specially crafted Web site to exploit this vulnerability and spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.


Affected software

Operational Decision Manager

How to mitigate CVE-2025-2824

Install updates from vendor's website.

Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 46, 8.11.1 Interim fix 44, 8.12.0.1 Interim fix 28, 9.0.0.1 Interim fix 11, 9.5.0.0 Interim fix 2

External References

Related Security Bulletins