CVE-2014-0905

IBM InfoSphere BigInsights 2.0-2.1.2 - Unauthenticated Cookie Transmission via Insecure LTPA Cookie Flag

Title source: llm
STIX 2.1

Description

IBM InfoSphere BigInsights 2.0 through 2.1.2 does not set the secure flag for the LTPA cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

References (2)

Core 2
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21680830
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/91720

Scores

EPSS 0.0053
EPSS Percentile 41.8%

Details

CWE
CWE-264
Status published
Products (4)
ibm/infosphere_biginsights 2.0.0.0
ibm/infosphere_biginsights 2.1.0.0
ibm/infosphere_biginsights 2.1.1.0
ibm/infosphere_biginsights 2.1.2.0
Published Aug 17, 2014
Tracked Since Feb 18, 2026