PT-2024-5325 · Ibm · Ibm Datacap Navigator

Published

2024-07-12

·

Updated

2024-09-18

·

CVE-2024-39734

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Datacap Navigator versions 9.1.5 through 9.1.9
Description The issue is related to the absence of the secure attribute in session cookies, allowing attackers to obtain cookie values by sending a http link to a user or by planting this link in a site the user visits. The cookie will be sent to the insecure link, and the attacker can then obtain the cookie value by snooping the traffic. This may enable a remote attacker to gain unauthorized access to protected information by intercepting session cookies.
Recommendations For IBM Datacap Navigator versions 9.1.5 through 9.1.9, consider setting the secure attribute on authorization tokens or session cookies to prevent them from being sent over insecure links. As a temporary workaround, restrict access to sensitive information and avoid using insecure links to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05953
CVE-2024-39734

Affected Products

Ibm Datacap Navigator