CVE-2025-2697

7.4

IBM · Cognos Command Center

IBM Cognos Command Center is vulnerable to an open redirect attack, which allows remote attackers to conduct phishing by spoofing trusted URLs to redirect users to malicious websites.

Executive summary

A vulnerability in IBM Cognos Command Center 10 allows unauthenticated attackers to perform open redirect attacks, potentially facilitating credential theft or secondary phishing campaigns.

Vulnerability

This is an open redirect vulnerability (CWE-601) that occurs when the application accepts user-supplied input to determine the destination of a redirect without proper validation. The vulnerability is exploitable by an unauthenticated attacker who can craft a malicious URL to deceive victims into visiting untrusted sites.

Business impact

The exploitation of this flaw can lead to significant reputational damage and the compromise of sensitive user information. By manipulating the redirect mechanism, attackers can create convincing phishing lures that appear to originate from the trusted IBM platform, increasing the success rate of social engineering attacks and potential unauthorized access to enterprise systems. The CVSS score of 7.4 reflects a high severity rating due to the potential for high impact on data integrity and user trust.

Remediation

Immediate Action: Upgrade to IBM Cognos Command Center 10.2.5 FP1 IF1, which contains the necessary security fixes and is available for download via IBM Fix Central.

Proactive Monitoring: Review web server and application access logs for unusual patterns of URL redirection or high volumes of requests targeting external domains following a reference to the Cognos Command Center host.

Compensating Controls: Implement strict URL validation policies at the Web Application Firewall (WAF) level to block requests containing suspicious redirect parameters or unauthorized destination domains.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing IBM Cognos Command Center 10.2.4.1 or 10.2.5 should prioritize the transition to version 10.2.5 FP1 IF1 immediately. Given the ease with which open redirects can be weaponized for phishing, failing to patch this vulnerability leaves the user base exposed to sophisticated social engineering attacks that bypass standard perimeter defenses.

More IBM CVEs

Sources