Open redirect in Apache Shiro - CVE-2023-46750
Published: January 14, 2024
Vulnerability details
The vulnerability allows a remote attacker to redirect victims to arbitrary URL.
The vulnerability exists due to improper sanitization of user-supplied data when "form" authentication is used. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain.
Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.
Affected software
Cognos Dashboards on Cloud Pak for Data
IBM Planning Analytics Workspace
Oracle WebCenter Sites
Oracle Adapter for Eclipse RDF4J
How to mitigate CVE-2023-46750
IBM Planning Analytics Workspace - update to 2.0.93