PT-2015-3325 · Red Hat · Red Hat Amq

Naftali Rosenbaum

·

Published

2015-07-31

·

Updated

2021-01-05

·

CVE-2015-5183

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat AMQ (affected versions not specified)
Description The issue is related to the absence of HTTPOnly and Secure attributes on cookies in the console of Red Hat AMQ. This could allow a remote attacker to reuse the session identifier of an authenticated user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02346
CVE-2015-5183

Affected Products

Red Hat Amq