IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to conduct phishing attacks and capture login credentials via an unspecified injection. Per: http://cwe.mitre.org/data/definitions/601.html
"CWE-601: URL Redirection to Untrusted Site ('Open Redirect')"
Publication date: Sat, 28 Jun 2014 05:55:00 +0000