← Back

CVE-2008-4284

nvd nist
Published: Feb 10, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:P
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x before 6.0.2.33, and 6.1.x before 6.1.0.23 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage feature.

Affected (109)

1 product
Websphere Application Server
Configuration A
109 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 5.0.0
Version 5.0.1
Version 5.0.2.10
Version 5.0.2.11
Version 5.0.2.12
Version 5.0.2.13
Version 5.0.2.14
Version 5.0.2.15
Version 5.0.2.16
Version 5.0.2.1
Version 5.0.2.2
Version 5.0.2.3
Version 5.0.2.4
Version 5.0.2.5
Version 5.0.2.6
Version 5.0.2.7
Version 5.0.2.8
Version 5.0.2.9
Version 5.0.2
Version 5.0
Version 5.0
Version 5.1.0.2
Version 5.1.0.3
Version 5.1.0.4
Version 5.1.0.5
Version 5.1.0
Version 5.1.1.10
Version 5.1.1.11
Version 5.1.1.12
Version 5.1.1.13
Version 5.1.1.14
Version 5.1.1.15
Version 5.1.1.16
Version 5.1.1.17
Version 5.1.1.18
Version 5.1.1.19
Version 5.1.1.1
Version 5.1.1
Version 6.0.0.1
Version 6.0.0.2
Version 6.0.0.3
Version 6.0.1.11
Version 6.0.1.13
Version 6.0.1.15
Version 6.0.1.17
Version 6.0.1.1
Version 6.0.1.2
Version 6.0.1.3
Version 6.0.1.5
Version 6.0.1.7
Version 6.0.1.9
Version 6.0.1
Version 6.0.2.11
Version 6.0.2.13
Version 6.0.2.15
Version 6.0.2.17
Version 6.0.2.19
Version 6.0.2.1
Version 6.0.2.22
Version 6.0.2.23
Version 6.0.2.24
Version 6.0.2.25
Version 6.0.2.27
Version 6.0.2.28
Version 6.0.2.29
Version 6.0.2.2
Version 6.0.2.30
Version 6.0.2.31
Version 6.0.2.32
Version 6.0.2.3
Version 6.0.2.4
Version 6.0.2.5
Version 6.0.2.6
Version 6.0.2.7
Version 6.0.2.9
Version 6.0.2
Version 6.0
Version 6.1.0.0
Version 6.1.0.10
Version 6.1.0.11
Version 6.1.0.12
Version 6.1.0.13
Version 6.1.0.14
Version 6.1.0.15
Version 6.1.0.16
Version 6.1.0.17
Version 6.1.0.18
Version 6.1.0.19
Version 6.1.0.1
Version 6.1.0.20
Version 6.1.0.21
Version 6.1.0.22
Version 6.1.0.2
Version 6.1.0.3
Version 6.1.0.4
Version 6.1.0.5
Version 6.1.0.6
Version 6.1.0.7
Version 6.1.0.8
Version 6.1.0.9
Version 6.1.0
Version 6.1.13
Version 6.1.14
Version 6.1.1
Version 6.1.3
Version 6.1.5
Version 6.1.6
Version 6.1.7
Version 6.1

References (8)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.