Vulnerabilities > CVE-2015-1993 - Unspecified vulnerability in IBM Security Qradar Incident Forensics

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ibm

Summary

IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session. <a href="https://cwe.mitre.org/data/definitions/614.html">CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute</a>

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:89761
last seen2017-11-19
modified2015-11-16
published2015-11-16
reporterRoot
titleIBM Security QRadar Incident Forensics中间人攻击漏洞(CVE-2015-1993)