CVE-2012-5936
IBM Sterling B2B Integrator 5.1-5.2 and Sterling File Gateway 2.1-2.2 - Session Cookie Secure Flag Not Set
Title source: llmDescription
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/80401
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21627985
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21640830
Scores
EPSS
0.0137
EPSS Percentile
69.0%
Details
CWE
CWE-310
Status
published
Products (4)
ibm/sterling_b2b_integrator
5.1
ibm/sterling_b2b_integrator
5.2
ibm/sterling_file_gateway
2.1
ibm/sterling_file_gateway
2.2
Published
Jul 03, 2013
Tracked Since
Feb 18, 2026