PT-2020-13951 · Ibm · Bigfix Inventory
Published
2020-12-16
·
Updated
2020-12-23
·
CVE-2020-14248
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BigFix Inventory versions up to 10.0.2
Description
The issue is related to BigFix Inventory not setting the secure flag for the session cookie in an https session. This can cause the cookie to be sent in http requests, making it easier for remote attackers to capture the cookie.
Recommendations
For BigFix Inventory versions up to 10.0.2, consider updating to a version that sets the secure flag for the session cookie to prevent it from being sent in http requests. As a temporary workaround, restrict access to sensitive information that could be compromised if the session cookie is captured.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bigfix Inventory