CVE-2012-5936

IBM Sterling B2B Integrator 5.1-5.2 and Sterling File Gateway 2.1-2.2 - Session Cookie Secure Flag Not Set

Title source: llm
STIX 2.1

Description

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/80401
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21627985
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21640830

Scores

EPSS 0.0137
EPSS Percentile 69.0%

Details

CWE
CWE-310
Status published
Products (4)
ibm/sterling_b2b_integrator 5.1
ibm/sterling_b2b_integrator 5.2
ibm/sterling_file_gateway 2.1
ibm/sterling_file_gateway 2.2
Published Jul 03, 2013
Tracked Since Feb 18, 2026