PT-2024-30361 · Ibm · Ibm Concert

Published

2024-09-12

·

Updated

2024-09-20

·

CVE-2024-43180

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Concert version 1.0
Description The issue concerns the exposure of sensitive cookie information due to the missing secure attribute on authorization tokens or session cookies. Attackers can exploit this by sending a user a http:// link or by planting this link in a site the user visits, allowing them to obtain the cookie value by snooping the traffic. This could lead to potential data compromise.
Recommendations For IBM Concert version 1.0, upgrade the affected component immediately to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the upgrade is applied.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-43180

Affected Products

Ibm Concert