CVE-2014-0905
IBM InfoSphere BigInsights 2.0-2.1.2 - Unauthenticated Cookie Transmission via Insecure LTPA Cookie Flag
Title source: llmDescription
IBM InfoSphere BigInsights 2.0 through 2.1.2 does not set the secure flag for the LTPA cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
References (2)
Core 2
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21680830
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/91720
Scores
EPSS
0.0053
EPSS Percentile
41.8%
Details
CWE
CWE-264
Status
published
Products (4)
ibm/infosphere_biginsights
2.0.0.0
ibm/infosphere_biginsights
2.1.0.0
ibm/infosphere_biginsights
2.1.1.0
ibm/infosphere_biginsights
2.1.2.0
Published
Aug 17, 2014
Tracked Since
Feb 18, 2026