PT-2024-11664 · Ibm · Ibm Aspera Console
Published
2024-09-24
·
Updated
2024-09-30
·
CVE-2022-43845
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Aspera Console versions 3.4.0 through 3.4.4
Description
The issue is caused by the failure to set the HTTPOnly flag, allowing a remote attacker to obtain sensitive information from the cookie. This could be exploited by a remote attacker to gain access to sensitive information.
Recommendations
For IBM Aspera Console versions 3.4.0 through 3.4.4, update to a version that sets the HTTPOnly flag to prevent sensitive information from being accessed.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Aspera Console