IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
History

Tue, 26 Aug 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 Aug 2025 17:00:00 +0000

Type Values Removed Values Added
Description IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Title IBM Cognos Command Center HTTP Open Redirect
First Time appeared Ibm
Ibm cognos Command Center
Weaknesses CWE-601
CPEs cpe:2.3:a:ibm:cognos_command_center:10.2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_command_center:10.2.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cognos Command Center
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-08-26T16:47:25.981Z

Updated: 2025-08-26T17:36:08.348Z

Reserved: 2025-03-23T16:28:25.483Z

Link: CVE-2025-2697

cve-icon Vulnrichment

Updated: 2025-08-26T17:36:05.780Z

cve-icon NVD

Status : Received

Published: 2025-08-26T17:15:37.320

Modified: 2025-08-26T17:15:37.320

Link: CVE-2025-2697

cve-icon Redhat

No data.