Required CVE Record Information
Description
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- securityfocus.com: 69642 vdb-entryx_transferred
- http://www-01.ibm.com/support/docview.wss?uid=swg24038045 x_transferred
- exchange.xforce.ibmcloud.com: ibm-rlksart-cve20140909-cookie(91872) vdb-entryx_transferred
- http://www-01.ibm.com/support/docview.wss?uid=swg21681449 x_transferred