CVE-2019-19613

CVSS v3 Score
5.2
Medium
CVSS v2 Score
4.3
Medium

Vulnerability Description

An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site after authentication. The attacker needs to be on the same network to modify the victim's request on the wire. Fixed in Release 24.2020.20608.0

CVSS:5.2(Medium)

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a special...

CVSS:5.3(Medium)

The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic...

CVSS:5.3(Medium)

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vuln...

CVSS:5.3(Medium)

URI.js is vulnerable to URL Redirection to Untrusted Site

CVSS:5.3(Medium)

url-parse is vulnerable to URL Redirection to Untrusted Site

CVSS:5.3(Medium)

forge is vulnerable to URL Redirection to Untrusted Site