IBM Rational Directory Server URI Redirection and Cross Site Scripting Vulnerabilities
15 Jun. 2012
Summary
IBM Rational Directory Server is prone to a URI-redirection vulnerability and a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.
Vulnerable Systems:
* IBM Rational Directory Server 5.2.0.2 and prior
Attackers can exploit these issues to execute arbitrary script or HTML code, steal cookie-based authentication credentials, and conduct phishing attacks. Other attacks may also be possible.
Vendor Status:
Currently we are not aware of any vendor-supplied patches.