CVE-2015-5183
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
Consola: Atributos de HTTPOnly y Secure no establecidos en las cookies de Red Hat AMQ.
It was found that Hawtio console does not set HTTPOnly or Secure attributes on cookies. An attacker could use this flaw to rerieve an authenticated user's SessionID, and possibly conduct further attacks with the permissions of the authenticated user.
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms. This release of Red Hat AMQ Broker 7.8.0 serves as a replacement for Red Hat AMQ Broker 7.7.0, and includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section. Issues addressed include cross site scripting and server-side request forgery vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-07-01 CVE Reserved
- 2017-09-25 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (8)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2018:2840 | 2023-11-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1249182 | 2020-12-08 | |
https://access.redhat.com/security/cve/CVE-2015-5183 | 2020-12-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Amq Search vendor "Redhat" for product "Amq" | < 6.3 Search vendor "Redhat" for product "Amq" and version " < 6.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss A-mq Search vendor "Redhat" for product "Jboss A-mq" | 7 Search vendor "Redhat" for product "Jboss A-mq" and version "7" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Web Server Search vendor "Redhat" for product "Jboss Enterprise Web Server" | 1.0.0 Search vendor "Redhat" for product "Jboss Enterprise Web Server" and version "1.0.0" | - |
Affected
|