CVE-2016-0351
LOWIBM Security Identity Manager Virtual Appliance <7.0.1.3-ISS-SIM-IF...
Title source: llmDescription
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21989198
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/111890
Scores
CVSS v3
3.7
EPSS
0.0105
EPSS Percentile
60.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (7)
ibm/security_identity_manager_virtual_appliance
7.0.0.0
ibm/security_identity_manager_virtual_appliance
7.0.0.1
ibm/security_identity_manager_virtual_appliance
7.0.0.2
ibm/security_identity_manager_virtual_appliance
7.0.0.3
ibm/security_identity_manager_virtual_appliance
7.0.1.0
ibm/security_identity_manager_virtual_appliance
7.0.1.1
ibm/security_identity_manager_virtual_appliance
7.0.1.3
Published
Feb 21, 2018
Tracked Since
Feb 18, 2026