CVE-2019-8283

MEDIUM

Gemalto Sentinel Ldk < 7.92 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.

Scores

CVSS v3 6.5
EPSS 0.0030
EPSS Percentile 52.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-732 CWE-1004
Status published
Products (1)
gemalto/sentinel_ldk < 7.92
Published Jun 07, 2019
Tracked Since Feb 18, 2026