CVE-2019-4616 - CERT CVE
ID CVE-2019-4616
Sažetak IBM Cloud Automation Manager 3.2.1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 168644.
Reference
CVSS
Base: 2.9
Impact: 2.9
Exploitability:5.5
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL NONE NONE
CVSS vektor AV:A/AC:M/Au:N/C:P/I:N/A:N
Zadnje važnije ažuriranje 24-08-2020 - 17:37
Objavljeno 05-02-2020 - 16:15