IBM Operational Decision Manager Open Redirect Vulnerability Allowing Phishing Attacks

Vulnerability

A vulnerability in IBM Operational Decision Manager versions 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could enable remote attackers to conduct phishing attacks by exploiting an open redirect flaw. This vulnerability allows attackers to spoof URLs, redirecting users to malicious websites that appear trustworthy. Such an attack could result in the theft of sensitive information or facilitate further attacks against the victim.

Impact

Exploitation of this vulnerability could lead to successful phishing attacks, allowing attackers to obtain sensitive information or conduct additional attacks against the victim.

Remediation

Users can apply the following interim fixes: - IBM Operational Decision Manager V8.11.0.1: Interim fix 046 - IBM Operational Decision Manager V8.11.1.0: Interim fix 044 - IBM Operational Decision Manager V8.12.0.1: Interim fix 028 - IBM Operational Decision Manager V9.0.0.1: Interim fix 011 - IBM Operational Decision Manager V9.5.0: Interim fix 002

Added: Aug 1, 2025, 7:19 PM
Updated: Aug 1, 2025, 7:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
0.6
exploitability
6.0
remediation
7.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.