CVE-2016-0351

LOW

IBM Security Identity Manager Virtual Appliance <7.0.1.3-ISS-SIM-IF...

Title source: llm
STIX 2.1

Description

IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21989198
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/111890

Scores

CVSS v3 3.7
EPSS 0.0105
EPSS Percentile 60.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (7)
ibm/security_identity_manager_virtual_appliance 7.0.0.0
ibm/security_identity_manager_virtual_appliance 7.0.0.1
ibm/security_identity_manager_virtual_appliance 7.0.0.2
ibm/security_identity_manager_virtual_appliance 7.0.0.3
ibm/security_identity_manager_virtual_appliance 7.0.1.0
ibm/security_identity_manager_virtual_appliance 7.0.1.1
ibm/security_identity_manager_virtual_appliance 7.0.1.3
Published Feb 21, 2018
Tracked Since Feb 18, 2026