Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2024-28770

больше 1 года назад

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-75j3-gff7-55x3

больше 1 года назад

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

CVSS3: 4.8
EPSS: Низкий
fstec логотип

BDU:2025-00939

больше 2 лет назад

Уязвимость программного средства синхронизации обмена идентификационными данными IBM Security Directory Integrator и программного средства интеграции данных IBM Security Verify Directory Integrator, связанная с отсутствием флага «Secure» в файлах cookie сеанса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-28770

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-75j3-gff7-55x3

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-00939

Уязвимость программного средства синхронизации обмена идентификационными данными IBM Security Directory Integrator и программного средства интеграции данных IBM Security Verify Directory Integrator, связанная с отсутствием флага «Secure» в файлах cookie сеанса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу