CVE-2025-2824 Details
Description
IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
A vulnerability in IBM Operational Decision Manager versions 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could enable remote attackers to conduct phishing attacks by exploiting an open redirect flaw. This vulnerability allows attackers to spoof URLs, redirecting users to malicious websites that appear trustworthy. Such an attack could result in the theft of sensitive information or facilitate further attacks against the victim.
Users can apply the following interim fixes: - IBM Operational Decision Manager V8.11.0.1: Interim fix 046 - IBM Operational Decision Manager V8.11.1.0: Interim fix 044 - IBM Operational Decision Manager V8.12.0.1: Interim fix 028 - IBM Operational Decision Manager V9.0.0.1: Interim fix 011 - IBM Operational Decision Manager V9.5.0: Interim fix 002
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7241286 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm operational decision manager | 8.11.0.1 8.11.1.0 8.12.0.1 9.0.0.1 9.5.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 14, 2025 | Initial Analysis | [email protected] |
| Aug 1, 2025 | New CVE Received | [email protected] |