An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legitimate KNIME Business Hub installation which, when opened by the user, redirects the user to a page of the attackers choice. This might open the possibility for fishing or other similar attacks. The problem has been fixed in KNIME Business Hub 1.16.0.
References
| Link | Resource |
|---|---|
| https://www.knime.com/security/advisories | Vendor Advisory |
Configurations
History
08 Oct 2025, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
| References | () https://www.knime.com/security/advisories - Vendor Advisory | |
| First Time |
Knime business Hub
Knime |
|
| CPE | cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:* |
02 Oct 2025, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-02 13:15
Updated : 2025-10-08 17:17
NVD link : CVE-2025-11240
Mitre link : CVE-2025-11240
CVE.ORG link : CVE-2025-11240
JSON object : View
Products Affected
knime
- business_hub
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
