CVE-2011-2941
published 2014-02-26CVE-2011-2941: Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites and…
PriorityP417medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.13%
62.7th percentile
Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the initialURI parameter.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_portal_platform | <= 5.1.1 | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5f7q-2xrc-wxhx: Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5
ghsa_unreviewed·2022-05-17
CVE-2011-2941 [MEDIUM] CWE-20 GHSA-5f7q-2xrc-wxhx: Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5
Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the initialURI parameter.
Red Hat
Platform: open URL redirect
vendor_redhat·2011-12-14·CVSS 5.8
CVE-2011-2941 [MEDIUM] Platform: open URL redirect
Platform: open URL redirect
Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the initialURI parameter.
No detection rules found.
No public exploits indexed.
2014-02-26
Published