PT-2020-18242 · Ibm · Ibm Curam Social Program Management
Published
2020-10-12
·
Updated
2020-10-26
·
CVE-2020-4780
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Curam Social Program Management versions 7.0.9 through 7.0.10
Description
The issue is related to the OOTB build scripts not setting the secure attribute on session cookies. This may allow unauthorized parties to observe cookies.
Recommendations
For versions 7.0.9 through 7.0.10, ensure the secure attribute is set on session cookies to prevent unauthorized observation.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Curam Social Program Management