Required CVE Record Information
Description
IBM Security Secret Server 10.7 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 170044.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
3.7 | LOW | 3.0 | CVSS:3.0/A:N/S:U/PR:N/UI:N/AC:H/I:N/C:L/AV:N/RL:O/E:U/RC:C |
References 2 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- https://www.ibm.com/support/pages/node/1283236 x_transferred
- exchange.xforce.ibmcloud.com: ibm-sss-cve20194638-info-disc (170044) vdb-entryx_transferred