Описание
IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Ссылки
- Broken Link
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Broken Link
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:ibm:workflow:-:*:*:*:*:bluemix:*:*
EPSS
Процентиль: 61%
0.00419
Низкий
8.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
больше 3 лет назад
IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
EPSS
Процентиль: 61%
0.00419
Низкий
8.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-287