IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers…
ibm·CWE-565·Published 2020-08-26
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 171825.
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 171825.
IBM Security Guardium Data Encryption (GDE) versión 3.0.0.2, no establece el atributo seguro en tokens de autorización o cookies de sesión. Los atacantes pueden ser capaces de obtener los valores de las cookies mediante el envío de un enlace http:// a un usuario o mediante la plantación de este enlace en un sitio al que el usuario accede. La cookie será enviada al enlace no seguro y el atacante podrá obtener el valor de la cookie mediante el rastreo del tráfico. IBM X-Force ID: 171825
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | NVD | 4.3 | 8.6 | 2.9 | AV:N/AC:M/Au:N/C:P/I:N/A:N |
| 3.0 | Primary | cve.org | 3.7 | — | — | CVSS:3.0/A:N/UI:N/C:L/PR:N/I:N/AC:H/S:U/AV:N/E:U/RC:C/RL:O |
| 3.0 | Primary | cve.org | 3.7 | — | — | CVSS:3.0/A:N/UI:N/C:L/PR:N/I:N/AC:H/S:U/AV:N/E:U/RC:C/RL:O |
| 3.0 | Secondary | NVD | 3.7 | 2.2 | 1.4 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | Primary | NVD | 4.3 | 2.8 | 1.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |