CVE-2019-8283

MEDIUM

Gemalto Sentinel LDK < 7.92 - Cookie Theft via Missing HttpOnly Flag

Title source: llm
STIX 2.1

Description

Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.

Scores

CVSS v3 6.5
EPSS 0.0119
EPSS Percentile 63.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-1004 CWE-732
Status published
Products (1)
gemalto/sentinel_ldk < 7.92
Published Jun 07, 2019
Tracked Since Feb 18, 2026