CVE-2022-26157

MEDIUM

Cherwell Service Mgmt <10.2.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie is not protected by the Secure flag. This makes it prone to interception by an attacker if traffic is sent over unencrypted channels.

Scores

CVSS v3 5.3
EPSS 0.0017
EPSS Percentile 37.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-311
Status published
Products (1)
cherwell/cherwell_service_management 10.2.3
Published Feb 28, 2022
Tracked Since Feb 18, 2026