← Vulnerability feed

Vulnerability record · CVE-2010-0715 · published 26 February 2010

CVE-2010-0715: Ibm websphere portal vulnerability

Ibm · Websphere Portal

Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the query string.

6.8 CVSS 2.0 Medium EPSS 1.3% · top 30.8%
6.8CVSS 2.0 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the query string.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-0715 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-1505Ibm lotus quickr vulnerabilityUnspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.27 services for Lotus Domino has unknown impact and attack vectors, aka SPR ESEO8DQME2.EPSS 1.8%10.0CVE-2008-5675Ibm websphere portal permissions and access controls vulnerabilityUnspecified vulnerability in IBM WebSphere Portal 6.0 before 6.0.1.5 has unknown impact and attack vectors related to "Access problems with BasicAuth…EPSS 1.5%9.3CVE-2012-2176Ibm lotus quickr memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote at…EPSS 31%8.8CVE-2017-1156Ibm websphere portal open redirect vulnerabilityIBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to …EPSS 1.1%8.8CVE-2016-2901Ibm websphere portal cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Man…EPSS 0.92%7.8CVE-2013-2951Ibm websphere portal vulnerabilityIBM WebSphere Portal 7.0.0.x and 8.0.0.x write passwords to a trace file when tracing is enabled for the Selfcare Portlet (Profile Management), which…EPSS 0.37%7.8CVE-2015-7419Ibm websphere portal vulnerabilityIBM WebSphere Portal 8.0.0.1 before CF19 and 8.5.0 before CF09 allows remote attackers to cause a denial of service (memory consumption) via crafted …EPSS 3.2%7.8CVE-2015-1943Ibm websphere portal vulnerabilityIBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF17, and 8.5.0 bef…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2010-0715), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.