CVE-2020-14248

MEDIUM

BigFix Platform 9.0.0-10.0.2 - Cleartext Transmission of Sensitive Information via Session Cookie

Title source: llm
STIX 2.1

Description

BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0013
EPSS Percentile 32.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-319
Status published
Products (1)
hcltech/bigfix_platform 9.0.0 - 10.0.2
Published Dec 16, 2020
Tracked Since Feb 18, 2026