Описание
Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.
Ссылки
- Permissions RequiredVendor Advisory
- Broken LinkVendor Advisory
- Permissions RequiredVendor Advisory
- Broken LinkVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:sap:disclosure_management:10.1:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00171
Низкий
6.3 Medium
CVSS3
5.4 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-1004
CWE-732
Связанные уязвимости
CVSS3: 5.4
github
больше 3 лет назад
Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.
EPSS
Процентиль: 39%
0.00171
Низкий
6.3 Medium
CVSS3
5.4 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-1004
CWE-732