CVE-2014-8489 – PingFederate 6.10.1 SP Endpoints Open Redirect
https://notcve.org/view.php?id=CVE-2014-8489
Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the TargetResource parameter. Vulnerabilidad de redirección abierta en startSSO.ping en SP Endpoints en Ping Identity PingFederate 6.10.1 permite a atacantes remotos redirigir usuarios hacia sitios web arbitrarios y realizar ataques de phishing a través de una URL en el parámetro TargetResource. PingFederate 6.10.1 SP Endpoints suffers from an insecure open redirection vulnerability. • http://packetstormsecurity.com/files/129454/PingFederate-6.10.1-SP-Endpoints-Open-Redirect.html http://seclists.org/fulldisclosure/2014/Dec/35 http://tetraph.com/security/cves/cve-2014-8489-ping-identity-corporation-pingfederate-6-10-1-sp-endpoints-dest-redirect-privilege-escalation-security-vulnerability •