Vulnerabilities > CVE-2015-1993 - Unspecified vulnerability in IBM Security Qradar Incident Forensics
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session. <a href="https://cwe.mitre.org/data/definitions/614.html">CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute</a>
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Seebug
bulletinFamily | exploit |
description | No description provided by source. |
id | SSV:89761 |
last seen | 2017-11-19 |
modified | 2015-11-16 |
published | 2015-11-16 |
reporter | Root |
title | IBM Security QRadar Incident Forensics中间人攻击漏洞(CVE-2015-1993) |