PT-2022-22686 · Ibm · Ibm Security Verify Information Queue

·

CVE-2022-35284

·

Published

2022-07-25

·

Updated

2022-08-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Verify Information Queue version 10.0.2
Description The issue could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.
Recommendations For IBM Security Verify Information Queue version 10.0.2, consider setting the SameSite attribute for sensitive cookies to restrict access and minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-35284

Affected Products

Ibm Security Verify Information Queue